Re: McAfee ESM is forwarding old events, behind by ~2 weeks
Although on 10.3.x we have the same issue with backlog (2-3 weeks), it didn't help to reduce the amount of forwarded events by tuning the forwarding. Even with small amount of EPS the backlog was still there.
Unfortunately we have got a major system outage for some other reason, but after restarting services and rebuilding DB, the backlog is not here anymore. Even when I changed "last forwarded event" to 2 days back to keep up, it has been handled ok and backlog is not there anymore. Forwarding forwards in near real-time.
Worth to mention, we did cp/db services restarts in a meanwhile and it did affect event fwd backlog. Maybe worth trying to change date back for couple of days and monitor will it keep up.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.