IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Defense: Does the Splunk App Get Command Line Data?

CB Defense: Does the Splunk App Get Command Line Data?

Environment

  • CB Defense PSC Backend: All Supported Versions

Question

Does the CB Defense App get the Command Line data from the CB Defense Notifications? 

Answer

The command line data is available via the Console and the CB Defense API but not the SIEM notification functionality 

Additional Notes

  • The CB Defense Notifications send over Alert Data which does not contain the command line path
  • The command line path is contained within the Event Data which is not sent to the Splunk App 
  • Event data is only available thru the CB Defense API and Console at this time

Related Content


Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
322
Contributors