Event Forwarder 3.8.2 is the initial release of containerized Event Forwarder, which is compatible with containerized Carbon Black EDR Server. Event Forwarder versions prior to 3.8.2 are not compatible with Carbon Black EDR containerized servers. Event Forwarder versions 3.8.2+ are supported.
Note: This topic describes how to install Event Forwarder 3.8.2. If you are using a later version of Event Forwarder, substitute that version number in the following steps.
Procedure
Results
- Configuration is saved in data/integrations/event-forwarder.
- The Carbon Black EDR data folder is re-used.
- Event Forwarder logs are available at data/logs/event-forwarder.
What to do next
To stop the Event Forwarder docker container, (when needed), go to the directory that contains the event-forwarder.yml file and issue the following command:
docker compose -f event-forwarder.yml down