<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306537#M2766</link>
    <description>&lt;P&gt;We currently use Splunk Enterprise Security (ES). &lt;/P&gt;

&lt;P&gt;When ingesting Carbon Black Protection (bit9) logs which Splunkbase app is best to use? What have been people's experiences?&lt;/P&gt;

&lt;P&gt;Should I go for the Cb Protection App for Splunk built by Carbon Black? Or should I go for the Splunk Add-on for Bit9 Carbon Black built by Splunk? &lt;/P&gt;

&lt;P&gt;I just need the data parsed and tagged correctly to the CIM data models. &lt;/P&gt;

&lt;P&gt;*As clarification Parity aka Bit9 aka Carbon Black Protection are the same product.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2017 18:17:36 GMT</pubDate>
    <dc:creator>wliu_ondeck</dc:creator>
    <dc:date>2017-03-30T18:17:36Z</dc:date>
    <item>
      <title>What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306537#M2766</link>
      <description>&lt;P&gt;We currently use Splunk Enterprise Security (ES). &lt;/P&gt;

&lt;P&gt;When ingesting Carbon Black Protection (bit9) logs which Splunkbase app is best to use? What have been people's experiences?&lt;/P&gt;

&lt;P&gt;Should I go for the Cb Protection App for Splunk built by Carbon Black? Or should I go for the Splunk Add-on for Bit9 Carbon Black built by Splunk? &lt;/P&gt;

&lt;P&gt;I just need the data parsed and tagged correctly to the CIM data models. &lt;/P&gt;

&lt;P&gt;*As clarification Parity aka Bit9 aka Carbon Black Protection are the same product.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 18:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306537#M2766</guid>
      <dc:creator>wliu_ondeck</dc:creator>
      <dc:date>2017-03-30T18:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306538#M2767</link>
      <description>&lt;P&gt;Use &lt;A href="https://splunkbase.splunk.com/app/2790/"&gt;https://splunkbase.splunk.com/app/2790/&lt;/A&gt;, as it is CIM compatible.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 19:29:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306538#M2767</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2017-03-30T19:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306539#M2768</link>
      <description>&lt;P&gt;Note that &lt;A href="https://splunkbase.splunk.com/app/2790/"&gt;https://splunkbase.splunk.com/app/2790/&lt;/A&gt; is the TA for Cb Response, &lt;EM&gt;not&lt;/EM&gt; Cb Protection. If you're integrating with Cb Protection, you want the &lt;A href="https://splunkbase.splunk.com/app/1790"&gt;Cb Protection App for Splunk&lt;/A&gt;. Sorry about the confusion.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 19:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306539#M2768</guid>
      <dc:creator>carbonblack</dc:creator>
      <dc:date>2017-03-30T19:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306540#M2769</link>
      <description>&lt;P&gt;Link not working  &lt;A href="https://splunkbase.splunk.com/app/2790"&gt;https://splunkbase.splunk.com/app/2790&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 15:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306540#M2769</guid>
      <dc:creator>robjackson</dc:creator>
      <dc:date>2017-04-27T15:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306541#M2770</link>
      <description>&lt;P&gt;Your clicking on the link which inserts an extra , comma at the end. Take out the comma at the end and it will work. &lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 15:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306541#M2770</guid>
      <dc:creator>wliu_ondeck</dc:creator>
      <dc:date>2017-04-27T15:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best Splunkbase app for Carbon Black Protection (bit9) and Splunk Enterprise Security integration?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306542#M2771</link>
      <description>&lt;P&gt;As per  Carbon black, TA is applicable for CB response product and not for the protection. We have a CB protection V7.2 so what is the TA we suppose to use get those logs CIM complaint. Thanks!!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 19:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-is-the-best-Splunkbase-app-for-Carbon-Black-Protection-bit9/m-p/306542#M2771</guid>
      <dc:creator>ravichandren</dc:creator>
      <dc:date>2017-12-07T19:48:39Z</dc:date>
    </item>
  </channel>
</rss>

