IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: SIEM/API Notifications Do Not Include EEDR Alert/Investigate URL

Carbon Black Cloud: SIEM/API Notifications Do Not Include EEDR Alert/Investigate URL

Environment

  • Carbon Black Cloud Console: All Supported Versions
  • VMware Carbon Black Cloud App for Splunk: 1.x
  • Splunk: 8.x

Symptoms

Alert URL is not included in the data sent to SIEM/API

Cause

The Data forwarder which is required to populate the Alert URL was not configured

Resolution

The below workaround can be followed:
  1. Copy the DEVICE_ID and ALERT_ID from the notification
  2. Navigate to the Investigate page
  3. Format a search query including the following search fields
  • device_id:{DEVICE_ID} AND alert_id:{ALERT_ID}

Related Content


Was this article helpful? Yes No
100% helpful (2/2)
Article Information
Author:
Creation Date:
‎09-26-2019
Views:
756
Contributors