Skip to content

This pack is targeted for collections of Carbon Black events

License

Notifications You must be signed in to change notification settings

criblpacks/cribl-carbon-black

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Carbon Black Pack


  • This pack is targeted for collections of Carbon Black events
  • The Carbon_Black pipeline inside the pack includes Sample files for testing and multiple examples of Dropping events
  • Furthermore, the pipeline show example of shaping the events into JSON before sending the event to the Analytics store

Important Information


Carbon Black Event types details can be found here: 
https://www.carbonblack.com/products/vmware-carbon-black-cloud-endpoint/

What to Expect


  • Event reduction: Expect 30% reduction in total size using Drop or Sampling.
  • Event shaping: Expect the pack to shape the events into JSON format

Requirements


Before you begin, ensure that you have met the following requirements:

  1. Create a Route with a filter for your Carbon Black Pack
  2. Select the CriblCarbonBlack pack as the pipeline.

Release Notes


Version 0.5.0 - 2021-07-10

Carbon Black events pack Initial release! Support for: VMWare Carbon Black events

Contributing to the Pack


Discuss this pack on our Community Slack channel

Contact


The author of this pack is Raanan Dagan and can be contacted at [email protected].

License


This Pack uses the following license: Apache 2.0.