Re: McAfee ESM is forwarding old events, behind by ~2 weeks
Although on 10.3.x we have the same issue with backlog (2-3 weeks), it didn't help to reduce the amount of forwarded events by tuning the forwarding. Even with small amount of EPS the backlog was still there.
Unfortunately we have got a major system outage for some other reason, but after restarting services and rebuilding DB, the backlog is not here anymore. Even when I changed "last forwarded event" to 2 days back to keep up, it has been handled ok and backlog is not there anymore. Forwarding forwards in near real-time.
Worth to mention, we did cp/db services restarts in a meanwhile and it did affect event fwd backlog. Maybe worth trying to change date back for couple of days and monitor will it keep up.