Environment
- Enterprise EDR Sensor: 3.4.0 and Higher
- Microsoft Windows: All supported versions
- Apple macOS: All supported versions
- Linux: All Supported Versions
Question
How much event and binary data will the sensor cache (or backlog) if it cannot transfer it to the backend servers?
Answer
- Windows Sensor: 1GB
- macOS Sensor: 500 MB
- Linux Sensor: 1 GB
Additional Notes
- Event data is stored in a .db file.
- If the file sizes above are exceeded, the oldest events are dropped in order to make room for newer, incoming events.
- The Windows Sensor limit is configurable via ConfigProp using RMS.