For endpoints where throttling is initiated, you can review the throttling status.
From the ePO - On-prem console, select Menu → Systems → System Tree.
On the Systems page, click the endpoint where throttling is initiated to view its details.
Click the Products tab.
Click the Solidcore row to view product details.
Review the values for the listed throttling properties.
Property
Description
Throttling Status: Events
Provides this information.
Cache usage
This indicates the percentage of event or request cache that is already used by the stored events or requests.
Number of dropped events or requests
When the cache usage reaches 100%, events or requests start dropping and the Data Dropped event is generated and displayed on the Threat Event Log and Solidcore Events pages.
Time when the threshold was reached
This indicates the time when event or request throttling was initiated.
Throttling Status: Policy Discovery (Observations)
Inventory Fetch Time (Last)
Indicates the time when the inventory was last fetched. When throttling of inventory updates is initiated, the Pull Inventory client task is disabled and you can't fetch the inventory until throttling resets.
Inventory Fetch Time (Next)
Indicates the time when you can fetch the inventory for the endpoint. When throttling of inventory updates resets (24 hours after the first inventory update was generated), the Pull Inventory client task is enabled again to allow you to fetch the inventory. In such scenarios, this property displays the time when throttling resets.