Is there a limit to the number of alerts that are pulled from the API on each sync when using the built-in Input?
Yes, 10,000. If your organization has more than 10,000 alerts each polling interval, you can do the following:
- Tune CB Analytics alerts that are known-good in your environment using the Dismiss all future alerts functionality.
- Follow recommendations from the Carbon Black Threat Research team.
- Modify the configured Alert Input and increase the Minimum Alert Severity.
- Change the polling interval from the default of 180 seconds to 120 or 60 seconds.
- Switch to ingesting Alerts via the Data Forwarder input.