Environment
- Hosted EDR: All Versions
- CB Event Forwarder: Version 3.x and Below
Question
What are the supported vendors for the CB Event Forwarder connector using Hosted EDR?
Answer
Vendor | Output Type | Output Format | Links |
---|
IBM Qradar |
|
|
|
Splunk |
- Splunk (recommended)
- S3
- Syslog
|
|
|
Sumo Logic |
|
|
|
LogRhythm |
|
|
|
RSA NetWitness |
|
|
|
Additional Notes
- Legacy Rsyslog templates (e.g., CEF) are no longer supported in CB Event Forwarder version 3.x.
- ArcSight, which uses Legacy Rsyslog, is no longer supported at this time.
Related Content