Skip to content
This repository has been archived by the owner on Mar 2, 2022. It is now read-only.

CB Logs 'Indicator' Information Addition to Splunk #3

Open
Justangatang opened this issue Sep 5, 2018 · 0 comments
Open

CB Logs 'Indicator' Information Addition to Splunk #3

Justangatang opened this issue Sep 5, 2018 · 0 comments

Comments

@Justangatang
Copy link

Hello,

Right now when we view Carbon Black events in Splunk, it provides a roll-up for each event, (e.g.'Threats'). The logs provide a list of 'Indicators', however with just minor information, example pic below:
image

Can any of the other information related to these indicators be sent to Splunk? We're looking for information such as:

  • The 'Application' column
    -- The executing process owner (possibly separated from the Application column)
  • The 'Event' column
    -- The connection details that each of the apps made. (possibly separated from the event column)

Example pic of the CB interface:
image

This would help us create better aggregation within the Splunk searches.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant