Dropped Events
Dropped events mean kprobe could not capture or deliver every kernel event.
Common causes
- event rate exceeds buffer capacity
- downstream pipeline unavailable
- agent CPU throttling
- storage or broker backpressure
- overly broad event capture policy
How to respond
- Check which event type is dropping.
- Increase agent buffer size.
- Confirm broker and storage health.
- Reduce capture scope if needed.
- Add node resources or shard storage.
Operational guidance
Short bursts of drops may be acceptable in broad monitoring mode. Sustained drops during an incident reduce forensic confidence and should be treated as an operational issue.