Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Endpoint Standard: How Does Event Suppression Work in Mac Sensors?

Endpoint Standard: How Does Event Suppression Work in Mac Sensors?

Environment

  • Endpoint Standard Sensor: All Supported Versions
  • Carbon Black Cloud: All Supported Versions
  • Apple macOS: All Supported Versions

Question

How does the sensor suppress events in order to reduce event noise?

Answer

  • To avoid excessive traffic, the repetitive, similar, events are suppressed, not reported to the cloud.
  • The suppression interval for process creation events is six hours.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-21-2020
Views:
484
Contributors