IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Getting Started With the Data Forwarder

Carbon Black Cloud: Getting Started With the Data Forwarder

Environment

  • Carbon Black Cloud Console: All Versions

Objective

How to get started with and best practices for the Carbon Black Cloud Data Forwarder. 

Resolution

Setup Overview:
  1. Decide on a use case and necessary Event Type for the Data Forwarder, such as Alert triage, SIEM integration, or watchlist reporting.
    • Alert: All available Alerts.
    • Endpoint Event: All available endpoint telemetry.
    • Watchlist Hit: All available Watchlist hits. 
  2. Configure your AWS S3 Bucket or Azure Blob Storage to receive data from Carbon Black Cloud.
  3. Add a Data Forwarder in the Carbon Black Cloud Console.
    Tip: If using the Endpoint Event forwarder type, there are three methods of configuring which data is sent.
  4. Fetch the forwarded data from the destination or connect other tools to process the data, including SIEM solutions like Splunk, QRadar, or ServiceNow.
Key Resources for Custom Query Data Filters: Key Resources for API:

Additional Notes


Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-02-2024
Views:
212
Contributors