Need to improve our management of active/inactive endpoint status based on executors #2234
Closed
Description
Description
We have 4 executors: OpenBAS agent, Caldera, Tanium and Crowdstrike.
These do not have the same way to handle health management.
Which poses a problem on our way to display active/inactive endpoint status.
The main rule on OBAS is : An endpoint that has not been pinged within three minutes is considered inactive.
This is related to our obas agent which pings every minute, but does not make sense with another executor which can ping every 5, 10 or X minutes.