Environment
- CB Defense PSC Backend: All Supported Versions
Question
Does the CB Defense App get the Command Line data from the CB Defense Notifications?
Answer
The command line data is available via the Console and the CB Defense API but not the SIEM notification functionality
Additional Notes
- The CB Defense Notifications send over Alert Data which does not contain the command line path
- The command line path is contained within the Event Data which is not sent to the Splunk App
- Event data is only available thru the CB Defense API and Console at this time
Related Content