EDR Linux Sensor: Core dumps created after upgrading to 7.1.0
EDR Linux Sensor: 7.1.0
Linux: All Supported Versions
Sensor occasionally creates large core dumps
Message reporting cbdaemon is generating core dump is reported in /var/log/messages file:
systemd: Started Process Core Dump (PID 1234/UID 0).
systemd: cbdaemon.service: Main process exited, code=killed, status=11/SEGV
cbdaemon.service: Killing process 12234 (ECStateEngine) with signal SIGKILL.
systemd: cbdaemon.service: Killing process 12334 (event_collector) with signal SIGKILL.
systemd-coredump: Failed to compress (unnamed temporary file): No space left on device
systemd-coredump: Process 2225 (cbdaemon) of user 0 dumped core
Issue with how the sensor handles file descriptors - CB-37984
This issue will be fixed in sensor version 7.1.1
As a workaround, core dumps on the sensor can be disabled.
Stop the cbdaemon service by executing
service cbdaemon stop
Create a wrapper script for cbdaemon for systemd to execute which will disable coredumps for cbdaemon. Put the following commands into /usr/sbin/cbdaemon.sh and make the file executable