Red Canary Outage History

Red Canary is up right now

Red Canary had 38 outages in the last 2 years totaling 281h 41m of downtime — averaging 1.6 incidents per month.

There were 38 Red Canary outages since June 5, 2024 totaling 281h 41m of downtime. Each is summarised below — incident details, duration, and resolution information.

Source: https://status.redcanary.com

Minor March 13, 2025

Ingestion Issues for Carbon Black Cloud Customers

Detected by Pingoru
Mar 13, 2025, 08:59 AM UTC
Resolved
Mar 14, 2025, 01:33 PM UTC
Duration
1d 4h
Affected: DetectionsVMware Carbon Black Cloud
Timeline · 5 updates
  1. monitoring Mar 13, 2025, 08:59 AM UTC

    We are investigating ingestion issues with Carbon Black Cloud. We are monitoring the Carbon Black Cloud status page and will provide updates when they are available. Sensor telemetry, events, and detections may be delayed.

  2. monitoring Mar 13, 2025, 10:02 AM UTC

    Carbon Black Cloud has implemented a fix and they are monitoring the service for stability. Ingestion of Carbon Black Cloud telemetry is no longer delayed. We will leave this incident open until Broadcom resolves theirs.

  3. monitoring Mar 13, 2025, 04:05 PM UTC

    Broadcom's incident remains in a monitoring state and we have been successfully ingesting and processing telemetry from Carbon Black Cloud for the past 6 hours. We will continue to leave this incident open while we monitor Broadcom's status.

  4. monitoring Mar 13, 2025, 10:39 PM UTC

    Broadcom's incident remains in a monitoring state and is being regularly checked for updates. Telemetry from Carbon Black Cloud is being successfully ingested and processed. We will provide additional updates when they are available.

  5. resolved Mar 14, 2025, 01:33 PM UTC

    Broadcom's incident remains in a monitoring state and we have not observed any errors on our end over the past 24 hours.

Read the full incident report →

Minor February 10, 2025

Alert Ingestion Delays Causing Failing Status Checks

Detected by Pingoru
Feb 10, 2025, 08:00 PM UTC
Resolved
Feb 10, 2025, 11:02 PM UTC
Duration
3h 2m
Affected: SentinelOneMicrosoftDetectionsProofpoint TAPCrowdstrike FalconLaceworkCarbon Black Cloud
Timeline · 4 updates
  1. identified Feb 10, 2025, 08:00 PM UTC

    We have identified an issue causing some alerts to fail ingestion, which may result in failing status checks for certain customers. Our team is actively testing a fix and assessing its impact. No alert data has been lost and all failed alerts will be reprocessed once the fix is implemented. Please note that detections based on these alerts may be delayed until ingestion is fully restored. We appreciate your patience and will provide further updates as they become available.

  2. monitoring Feb 10, 2025, 08:41 PM UTC

    We have successfully deployed a fix for the alert ingestion issue and alerts are now being ingested. Detections may still be delayed while we process the backlog of failed alerts. In addition, status checks that appeared to fail during this incident will automatically resolve; no customer action is required. We will continue to monitor the situation and will close this incident once all backlogged alerts have been ingested.

  3. monitoring Feb 10, 2025, 08:42 PM UTC

    We have successfully deployed a fix for the alert ingestion issue and alerts are now being ingested. Detections may still be delayed while we process the backlog of failed alerts. In addition, status checks that appeared to fail during this incident will automatically resolve; no customer action is required. We will continue to monitor the situation and will close this incident once all backlogged alerts have been ingested.

  4. resolved Feb 10, 2025, 11:02 PM UTC

    This incident has been resolved and all backlogged alerts processed.

Read the full incident report →

Minor February 9, 2025

Delayed Telemetry Processing for Multiple Telemetry Sources

Detected by Pingoru
Feb 09, 2025, 04:42 AM UTC
Resolved
Feb 09, 2025, 02:58 PM UTC
Duration
10h 15m
Affected: DetectionsVMware Carbon Black CloudMicrosoft Office 365CrowdStrike FalconAmazon Web ServicesMicrosoftMicrosoft AzureSentinelOneTrend Micro Endpoint Detection and ResponseJamf Threat DefenseRed Canary Linux EDR
Timeline · 4 updates
  1. investigating Feb 09, 2025, 04:42 AM UTC

    We have identified an issue that is causing delayed telemetry processing for Carbon Black Cloud EDR, Microsoft Defender for Endpoint, Microsoft Office365, SentinelOne, CrowdStrike, TrendMicro, AWS, Microsoft Azure, Jamf, and Linux EDR. This delay in telemetry may cause potential delays in detecting threats based on this telemetry. We are investigating the cause of this issue currently and will provide updates as we know more and are able to take action to address the issue.

  2. investigating Feb 09, 2025, 04:43 AM UTC

    We are continuing to investigate this issue.

  3. monitoring Feb 09, 2025, 05:40 AM UTC

    A fix has been implemented and we are monitoring the results.

  4. resolved Feb 09, 2025, 02:58 PM UTC

    This incident has been resolved.

Read the full incident report →

Minor January 10, 2025

Tracking an external incident with Broadcom Carbon Black Cloud

Detected by Pingoru
Jan 10, 2025, 05:24 PM UTC
Resolved
Jan 12, 2025, 06:09 PM UTC
Duration
2d
Affected: Carbon Black Cloud
Timeline · 4 updates
  1. identified Jan 10, 2025, 05:24 PM UTC

    We are tracking an outage with Broadcom Carbon Black Cloud (CbC) that is affecting alert ingest and correlation of alerts to endpoint data. https://status.broadcom.com/services/carbon-black/notices/kcjrp2fn7pniepsu-carbon-black-cloud-alerts-page-search-degraded-performance

  2. identified Jan 10, 2025, 06:47 PM UTC

    Broadcom Carbon Black continues to investigate this issue.

  3. monitoring Jan 11, 2025, 01:11 PM UTC

    After a few false starts, Broadcom has shifted their incident to "Monitoring". We have been successfully ingesting and correlating alerts for the past 5 hours. We will leave this incident open until Broadcom resolves theirs.

  4. resolved Jan 12, 2025, 06:09 PM UTC

    Broadcom's incident remains in a monitoring state and we have not observed any errors on our end over the past 24 hours.

Read the full incident report →

Minor November 6, 2024

Alert ingestion Issues for Microsoft Defender for Endpoint Customers

Detected by Pingoru
Nov 06, 2024, 02:32 PM UTC
Resolved
Nov 07, 2024, 01:00 AM UTC
Duration
10h 27m
Affected: DetectionsMicrosoft
Timeline · 3 updates
  1. investigating Nov 06, 2024, 02:32 PM UTC

    We are investigating ingestion issues of alerts from Microsoft Graph V2. We have notified the Microsoft support team and are working with them to resolve the issue promptly. Process execution (EDR) telemetry is still being ingested and processed by Red Canary. Detection of threats from Microsoft Graph V2 alerts may be delayed.

  2. investigating Nov 06, 2024, 06:36 PM UTC

    We are continuing to monitor the status of this ingestion issue with Microsoft Graph V2 alerts. At this time there is no update.

  3. resolved Nov 07, 2024, 01:00 AM UTC

    This incident has been resolved.

Read the full incident report →

Minor October 30, 2024

Ingestion Delays for JAMF Telemetry

Detected by Pingoru
Oct 30, 2024, 07:32 PM UTC
Resolved
Oct 31, 2024, 11:04 AM UTC
Duration
15h 31m
Affected: Detections
Timeline · 2 updates
  1. identified Oct 30, 2024, 07:32 PM UTC

    We are currently monitoring an operational incident with Jamf (https://status.jamf.com/) that is impacting our ability to ingest telemetry for Jamf customers. Detection for these customers may be delayed until the issue is resolved. This incident will be updated as additional information becomes available from Jamf.

  2. resolved Oct 31, 2024, 11:04 AM UTC

    We have confirmed that we are now ingesting telemetry from JAMF.

Read the full incident report →

Minor October 7, 2024

Detection delayed

Detected by Pingoru
Oct 07, 2024, 08:31 PM UTC
Resolved
Oct 07, 2024, 10:54 PM UTC
Duration
2h 22m
Affected: Detections
Timeline · 4 updates
  1. investigating Oct 07, 2024, 08:31 PM UTC

    We are currently experiencing processing delays, which may cause late detection notifications for some customers. We will provide updates as more information becomes available.

  2. identified Oct 07, 2024, 09:19 PM UTC

    The issue has been identified and a fix is being implemented.

  3. monitoring Oct 07, 2024, 09:32 PM UTC

    A fix has been implemented and we are monitoring the results.

  4. resolved Oct 07, 2024, 10:54 PM UTC

    This incident has been resolved.

Read the full incident report →

Minor October 4, 2024

Web Portal / API request timeouts

Detected by Pingoru
Oct 04, 2024, 03:25 PM UTC
Resolved
Oct 04, 2024, 06:04 PM UTC
Duration
2h 38m
Affected: Web PortalAPI Requests
Timeline · 3 updates
  1. investigating Oct 04, 2024, 03:25 PM UTC

    We are investigating reports that Red Canary web portal and API requests are failing for some customers. We will update this page as we learn more.

  2. identified Oct 04, 2024, 04:51 PM UTC

    The issue has been identified and a fix is being implemented.

  3. resolved Oct 04, 2024, 06:04 PM UTC

    This incident has been resolved.

Read the full incident report →

Notice September 30, 2024

Detection Delayed

Detected by Pingoru
Sep 30, 2024, 10:45 PM UTC
Resolved
Oct 01, 2024, 03:02 AM UTC
Duration
4h 16m
Affected: Detections
Timeline · 3 updates
  1. investigating Sep 30, 2024, 10:45 PM UTC

    We are currently experiencing data processing delays, resulting in late detection notification to some customers. This incident will be updated as additional information becomes available.

  2. monitoring Sep 30, 2024, 11:29 PM UTC

    A fix has been implemented and we are monitoring the results. At this time detections may be delayed for some customers.

  3. resolved Oct 01, 2024, 03:02 AM UTC

    This incident has been resolved.

Read the full incident report →

Critical September 18, 2024

Issues accessing the Red Canary portal

Detected by Pingoru
Sep 18, 2024, 04:07 PM UTC
Resolved
Sep 18, 2024, 04:22 PM UTC
Duration
15m
Affected: Web PortalAPI Requests
Timeline · 2 updates
  1. identified Sep 18, 2024, 04:07 PM UTC

    We are aware of an incident causing issues accessing the Red Canary web portal. We have identified the issue and are working on a fix. Data processing and detections are not affected at this time.

  2. resolved Sep 18, 2024, 04:22 PM UTC

    This incident has been resolved.

Read the full incident report →

Notice July 19, 2024

Red Canary is not directly impacted by the CrowdStrike-caused outage

Detected by Pingoru
Jul 19, 2024, 05:04 PM UTC
Resolved
Jul 25, 2024, 09:15 PM UTC
Duration
6d 4h
Affected: CrowdStrike Falcon
Timeline · 2 updates
  1. monitoring Jul 19, 2024, 05:04 PM UTC

    Red Canary is not directly impacted by the CrowdStrike-caused outage. We are monitoring customer environments and will receive telemetry from affected CrowdStrike endpoints as they come back online.

  2. resolved Jul 25, 2024, 09:15 PM UTC

    This incident has been resolved.

Read the full incident report →

Minor July 19, 2024

Detection delayed for Microsoft sources

Detected by Pingoru
Jul 19, 2024, 01:07 AM UTC
Resolved
Jul 19, 2024, 04:29 AM UTC
Duration
3h 21m
Affected: Microsoft
Timeline · 3 updates
  1. investigating Jul 19, 2024, 01:07 AM UTC

    We are currently experiencing data processing delays for Microsoft Defender for Endpoint and Microsoft Azure telemetry. This may result in late detection notifications to some customers. We are following a Microsoft incident as the likely cause. https://azure.status.microsoft/en-us/status This incident will be updated as additional information becomes available.

  2. monitoring Jul 19, 2024, 03:23 AM UTC

    Microsoft reports they have identified the issue and are actively applying mitigations. We are starting to see data flowing again. We will continue to monitor the situation and resolve this incident when we are confident services are fully restored.

  3. resolved Jul 19, 2024, 04:29 AM UTC

    This incident has been resolved.

Read the full incident report →

Notice June 26, 2024

Reports of Endpoints Showing as Unmonitored

Detected by Pingoru
Jun 26, 2024, 06:37 PM UTC
Resolved
Jun 26, 2024, 10:37 PM UTC
Duration
4h
Affected: Web PortalVMware Carbon Black Response hosted by Red CanaryVMware Carbon Black Hosted EDRVMware Carbon Black CloudCrowdStrike FalconMicrosoftSentinelOnePalo Alto Networks Cortex XDR
Timeline · 3 updates
  1. identified Jun 26, 2024, 06:37 PM UTC

    We are currently investigating an issue where endpoints are showing as unmonitored. This is a display issue only. Telemetry ingestion, processing, analysis, and detection are all working as expected.

  2. monitoring Jun 26, 2024, 07:32 PM UTC

    A fix is being implemented and we are monitoring the results.

  3. resolved Jun 26, 2024, 10:37 PM UTC

    The issue around endpoints incorrectly showing as unmonitored has been fixed and this incident is now resolved.

Read the full incident report →