All Apps and Add-ons

SOAR App : Carbon Black Response : Can't quarantine/unquarantine if device offline

PeterL
New Member

The Carbon Black Response app for SOAR doesn't allow you to quarantine/unquarantine if the device is offline. In the Carbon Black interface/api this is just a flag that is set, so if they are offline it prevents them from re-connecting. This is the desired behaviour but seems from the Carbon Black Response app code that a check to see if online has been added. Can this be removed?

Labels (1)
0 Karma

marnall
Builder

Certainly, you can edit the app code by cloning the app into a draft and then editing the carbonblack_connector.py file.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...