Carbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDR
Issue/Introduction
What kind of data/events can a Linux sensor capture?
Environment
Carbon Black Cloud Linux Sensor: All Versions
Resolution
There are two types of data we receive from the sensor: metaData and event type data.
MetaData (searchable in the console via fields like: process_name, process_hash, device_name, etc.), is consistent for the life of the process or device.
Event type data (searchable in the console via fields like: childproc, blocked/terminate, netconn, modload, etc.) are unique for every event.
Table below shows all event types and which are supported by the Linux sensor.