Environment
- Carbon Black Cloud Console
- Carbon Black Cloud Splunk Plug-in
- Carbon Black Cloud QRadar Plug-in
- Carbon Black Cloud 3rd Party API Users
Symptoms
Device_username field does not have the current user.
Cause
Alerts show user who installed the product rather than logged-in user.
Resolution
- Console update: Run By will be replaced by Process username as part of UAE 3.0 Release due in Aug 2023.
- API queried results will be updated as CBC Plug-ins for QRadar, Splunk and other 3rd party tools are updated to utilze the new API V7 calls.
Additional Notes
- The v7 alert API will include a process_username field which is the user that ran the process of the alert, rather than the user that installed the device.
- The API's are available now and when the Plugins get updated this change should appear.
- More information can be found in the related content below.
Related Content