Hi Kevin,
Thank you again for the clarification.
To answer your question about the phrase “system fell behind” — that was imprecise wording on my part. What I actually meant was our own client falling behind, resulting in the kernel dropping events because our ES client could not keep up with the message rate. I wasn’t suggesting that the kernel itself was falling behind. Your explanation makes that distinction very clear, and seq_num is exactly the signal I was looking for.
This clears up what I was trying to understand and gives us a much clearer direction for how we represent monitoring coverage in our audit product. We’ll use the per-client, per-event-type sequence numbers as the authoritative indicator of event loss, while recording agent lifecycle events separately rather than trying to infer a generic “system lag.”
I really appreciate your guidance throughout these discussions. It has been extremely valuable in helping us build on Endpoint Security in a way that aligns with Apple’s design.
Best regards,
Kei
Topic:
App & System Services
SubTopic:
Core OS
Tags: