EDR: What data is lost if the primary node in a cluster need to be restored?
EDR Server: 7.x
What data will be lost if a primary node in a cluster must be restored if all the other nodes are running?
In an eventless primary node
Any changes in the UI would be lost, i.e., watchlists, new sensor groups, etc.
Any binary files and metadata uploaded since the backup
In a primary node with events all of the above as well as process events would be lost
Some event data can be copied over from the minions. Cbmodules is synced over to the minions, so that can be copied over to the primary node. Any binaries themselves from the downtime would be lost, but metadata would still be there. New sensors seeing binary would upload the files.
If building a new primary node, copy certs from the minions. This should allow sensors to still check into the server, but would check in under the default group.