IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Cb Defense: How to collect events for a specific endpoint

Cb Defense: How to collect events for a specific endpoint

Environment

  • PSC Web Console: All versions
  • PSC Sensor: All Supported Versions
  • Microsoft Windows: All Supported Versions
  • Apple MacOS: All Supported Versions

Objective

  • You want to collect events for a specific endpoint for Auditing or Incident Response Reasons

Resolution

  • At this time, you will need to use our APIs to get the event information you would like from the endpoint

Additional Notes

  • You can collect events from a specific endpoint using our API or our CbAPI Python Module
  • Please refer to the links in the "Related Content" section below on how to get started, as well as examples.
  • An idea has been submitted to provide event export functionality in the PSC. The link for this idea is in "Related Content".

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-04-2019
Views:
576
Contributors