Security Connect 2021 is coming Jun 3. Register for free today!

Carbon Black Cloud: Can Watchlist Hits be Sent to a SIEM?

Carbon Black Cloud: Can Watchlist Hits be Sent to a SIEM?

Environment

  • Carbon Black Cloud Console: All Versions

Question

Do Notifications send Watchlist hits to a SIEM without Watchlists configured with alerts? 

Answer

  • Watchlist hits cannot be sent directly to a SIEM from the console notifications
  • Watchlist hits can be configured to create alerts which can be sent via notifications
  • The Event Forwarder can be used to sent watchlist hits

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎04-16-2021
Views:
60