Carbon Black Cloud: Is it Possible to Send Audit Logs to a SIEM?
book
Article ID: 289249
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
Can the audit logs be sent over to a SIEM?
Environment
- Carbon Black Cloud Console: All Versions
Resolution
- The new Syslog connector now supports audit logs as long as an API and SIEM key are configured.
- The instructions for the new syslog are here
Feedback
thumb_up
Yes
thumb_down
No