Carbon Black
Carbon Black is a source for endpoint protection that can be forwarded into Splunk for correlation with other security indicators and for alerting on detections of attacks. The Carbon Black event data is forwarded to Splunk by universal forwarders in JSON format. Carbon Black provides fields and tags in the endpoint security domain focusing on intrusion detection, system changes used for malware detection, and investigation. It also monitors network traffic, does protocol analysis, and tracks and alerts on application behavior. In the Common Information Model, Carbon Black can be mapped to any of the following data models, depending on the field: Alerts, Intrusion Detection, Change, Network Traffic, Endpoint. Any use cases that leverage these data models could work directly or with minor adjustments.
Getting data in
Source | Add-ons and Apps | Guidance |
---|---|---|
Carbon Black |
Splunk platform Splunk SOAR |
Configuration Use Cases |
VMware Carbon Black Cloud |
Splunk platform |
|
VMware Carbon Black EDR |
Splunk platform |