Hosted: EDR How to Enable the Splunk HEC Connector in a Hosted EDR console
book
Article ID: 284859
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Enable Splunk HEC connector from within a Hosted EDR console
Environment
- Hosted EDR (formerly CB Response Cloud): All Versions
- Splunk: All Supported Versions
Resolution
- From the console click on the event forwarder link
- Click edit
- Drop down 'Type' Select Splunk
- Add the URL of the 'Splunk HEC endpoint
- Add the 'HEC token
- Add the server 'Common Name' (FQDN of the Hosted EDR server)
- Configure 'Send timeout setting'
- Configure 'Max bundle size'
- Configure security settings as per your organizational requirements
- Click Save
- Verify data begins flowing to Splunk
Additional Information
- As of Hosted EDR version 7.1.0 console administrators can configure the Event Forwarder from the console no support case is required
- If the IP of the cloud server is needed perform an nslookup on sensors.fqdn
Feedback
thumb_up
Yes
thumb_down
No