Does theSplunkAdd-onfor Bit9 CarbonBlackformat the CB JSON md5 field to either Malware.file_hash or Email.file_hash? hPer theCarbonBlack (CB) API reference and JSON response example, the CB J...
Hi, our company does not yet have Splunk enterprise security, but we are considering getting it. Currently, our security posture includes a stream of EDR data from CarbonBlack containing the EDR e...
...Cb Protection App forSplunk built by CarbonBlack? Or should I go fortheSplunkAdd-onfor Bit9 CarbonBlack built by Splunk?
I just need the data parsed and tagged correctly to the CIM d...
I have received multiple errors while trying to install theCarbonBlack agent on two indexers.
The first error is this:
error: db5 error(11) from dbenv->open: Resource temporarily u...
We need to collect VMWare CarbonBlack Cloud events to Splunk (Cloud) We use this app https://splunkbase.splunk.com/app/5332 on heavy forwarder to configure inputs. If we have a d...
index=xxxx sourcetype="Script:InstalledApps" DisplayName="CarbonBlack Cloud Sensor 64-bit" I am trying to get the list/name of host that doesnt have CarbonBlack installed. Can someone help me w...
I have been having issues with my splunk where thesplunk service stops randomly. here are some logs from splunkd.log right before it went down.
Mostly uses Splunk with CarbonBlackadd-on to g...
I am trying to access CarbonBlack via The REST API. As expected, this works in Postman:
Console Output (keys and tokens changed):
GET
https://api-prod06.conferdeploy.net/integrationServices/v...
...ttp_access_management logs were recorded with dates for each day, where as carbon.log is today's log, and old dated logs are older logs.
to monitor http_access logs i am using the below command
./splunkadd m...
Hi
We are using Vmware carbonblack cloud app and the vmware logs are pulled from AWS s3 buckets. The index is having logs. However, the dashboards of the app when configured with same i...