Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: Will sensor record new events after disk filled up due to event submission failure to server?

EDR: Will sensor record new events after disk filled up due to event submission failure to server?

Environment

  • EDR sensor: All supported versions

Question

EDR: Will sensor record new events after disk filled up due to event submission failure to server?

Answer

No, new events would be dropped and the old events are kept.

Additional Notes

  • Once a sensor gets a 200 for reserve calls, it submits the data to the server via a submit2 call and deletes the event data locally.
  • Once a sensor gets a 400/500 error from the server where it can't submit, it will hold the events to disk up until the set storage size in the sensor groups, 2% of disk or 500MB by default, whichever it hits first.
  • New events would be dropped and the old ones are kept if sensor cannot submit to server.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-30-2022
Views:
102
Contributors