You can determine if throttling is initiated for any endpoint in your setup and you can take action to manage the feature.
Determine if throttling is initiated and identify the affected endpoints.
Event
Description
Data Throttled
Generated for an endpoint when event or policy discovery request throttling is initiated. After throttling resets, this event is generated daily until the cache is empty.
Data Dropped
Generated when the cache is full and the oldest data is dropped from the event cache.
Review the throttling status for each affected endpoint.
Process data generated for affected endpoints and create relevant rules. You must process data quickly to make sure that data isn't dropped.