Is there a limit to the number of alerts that are pulled from the API on each sync when using the built-in Input?

Yes, 10,000. If your organization has more than 10,000 alerts each polling interval, you can do the following:

  • Tune CB Analytics alerts that are known-good in your environment using the Dismiss all future alerts functionality.
  • Follow recommendations from the Carbon Black Threat Research team.
  • Modify the configured Alert Input and increase the Minimum Alert Severity.
  • Change the polling interval from the default of 180 seconds to 120 or 60 seconds.
  • Switch to ingesting Alerts via the Data Forwarder input.