When Logon Tracker first runs on an endpoint, it can parse existing logs to identify the logon history for that endpoint. Backfill is enabled by default.
Note
Disabling backfill is not recommended.
Capturing historical logon activity is critical to investigating lateral movement.
Disabling event enrichment
When the Disabling Event Enrichment setting is turned on, it will disable advanced enrichment on the endpoints. Advanced enrichment uses multiple sources of event data to enhance events with additional metadata. Disabling the advanced enrichment improves performance of the endpoint.
Maximum cache size
The Maximum Cache Size setting controls the maximum number of unique events the endpoint will hold in its cache before older events are removed. This setting directly affects the memory footprints of the endpoint for the Logon Tracker process. The default cache size is 5,000,000 unique events.