All Apps and Add-ons

Why is VMware Carbon Black Cloud eventtypes not applying correctly?

poconnell_t
Engager

I'm having issues with eventtypes not correctly being applied from VMware Carbon Black Cloud ingest that I can't figure out, as each search in the chain successfully finds events. These are the three eventtypes that chain together. The first two apply correctly (vmware_cbc_base_index, vmware_cbc_alerts), but not the third (vmware_cbc_malware).

From eventtypes.conf:

 

 

[vmware_cbc_base_index]
search = index=carbonblack_audit

[vmware_cbc_alerts]
search = eventtype=vmware_cbc_base_index sourcetype="vmware:cbc:s3:alerts" OR sourcetype="vmware:cbc:alerts"

[vmware_cbc_malware]
search = eventtype=vmware_cbc_alerts threat_cause_threat_category="*MALWARE*" NOT threat_cause_threat_category="*NON_MALWARE*"

 
 When I use the search in the third eventtype (vmware_cbc_malware), I do get events. Search:
eventtype=vmware_cbc_alerts threat_cause_threat_category="*MALWARE*" NOT threat_cause_threat_category="*NON_MALWARE*"
| stats count by eventtype

  
eventtype count
vmware_cbc_alerts 65
vmware_cbc_base_index 65

Can anyone help me figure out why this third eventtype is not being applied?

 
Labels (2)
Tags (1)
0 Karma
1 Solution

poconnell_t
Engager

Sigh, nevermind, this was an issue with exports in default.meta.

View solution in original post

0 Karma

poconnell_t
Engager

Sigh, nevermind, this was an issue with exports in default.meta.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...