Environment
Question
Does Carbon Black guarantee 30 days of retention for events in Hosted EDR environments?
Answer
- 30 days of retention is not always guaranteed.
- The Hosted EDR environments are resourced to maintain 30 days of data assuming that endpoints are submitting reasonable amounts of data. For highly active endpoints further event filtering may need to take place in order to maintain 30 days of event retention
Additional Notes
- Event retention can be increased by minimizing some incoming data through a few methods
- Adjust retention settings in sensor groups under Advanced > Retention Maximization
- In sensor group settings select Advanced > Filter known modloads
- Apply Ingress filtering for noisy events which are deemed safe
Related Content