Environment
- Carbon Black Cloud console: All versions
- VMware Carbon Black Cloud App for Splunk: 1.x
- Splunk: 8.x
Symptoms
- Carbon Black data does not appear in Splunk dashboards interface
- Splunk Indices show 0 entries
- No relevant errors appear in the UI or backend logs
Cause
Incorrect index is configured for Alerts Inputs
Resolution
- Log into Splunk and open VMware Carbon Black Cloud App for Splunk
- Open VMware CBC Base Configuration tab
- Verify name of VMware CBC Base Index
- Open Alerts Inputs tab
- Change Index listed for the Alerts Ingest Configuration to VMware CBC Base Index
Additional Notes
The VMware CBC Base Configuration section also contains Alert Action Index, however this is for Splunk-generated alerts and should not be confused with incoming alerts from CBC
Related Content