Hi.
I've just configured Syslog to SplunkonCarbonBlack server. Also, the TA has been installed on my Splunk servers.
The CarbonBlack events are making it to Splunk as expected, but none o...
The documentation for this add-onon apps.splunk.com says there are pre-built dashboards yet apps.conf sets is_visible=false suggesting no dashboards.
Can anyone clarify?
Thanks!
Hello,
in splunkbase download page (https://splunkbase.splunk.com/app/3545/) mention support for cim 4.9.
After installing add-on, i dont see any fields extraction\alias for cim compatible.
a...
It would appear that at 03:15 UTC or so on 12/20/2019 calls to the integrations/v3 API started returning an error 503 for us. We had heard that they were planning to depreciate the v3 API's, but t...
...nstructions from RedCanary (https://www.redcanary.com/blog/carbon-black-response-splunk-integration/), we tried grabbing process starts and network connections.
6 minutes of data was 1GB --thats on track for...
Dear Experts ,
I have installed the SplunkAdd-onfor Bit9 CarbonBlack and I have installed the CarbonBlack Event Forwarder utility on the CarbonBlack Server. Issue is that agent is not g...
We need to collect VMWare CarbonBlack Cloud events to Splunk (Cloud) We use this app https://splunkbase.splunk.com/app/5332 on heavy forwarder to configure inputs. If we have a d...
Went through this guide (https://splunkbase.splunk.com/app/3545/) , but we are still not getting any data from CarbonBlack Defense (cloud). Any recommendations?
Does the SplunkAdd-onfor Bit9 CarbonBlackformat the CB JSON md5 field to either Malware.file_hash or Email.file_hash? hPer the CarbonBlack (CB) API reference and JSON response example, the CB J...