Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Defense: Does the Splunk App Get Command Line Data?

CB Defense: Does the Splunk App Get Command Line Data?

Environment

  • CB Defense PSC Backend: All Supported Versions

Question

Does the CB Defense App get the Command Line data from the CB Defense Notifications? 

Answer

The command line data is available via the Console and the CB Defense API but not the SIEM notification functionality 

Additional Notes

  • The CB Defense Notifications send over Alert Data which does not contain the command line path
  • The command line path is contained within the Event Data which is not sent to the Splunk App 
  • Event data is only available thru the CB Defense API and Console at this time

Related Content


Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
269
Contributors