AppControl: Can Rule Activity Be Reported in Automation?
book
Article ID: 290560
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Can the activity of software rules be reported on a time-frame basis, for example a monthly report of File Integrity Control rule activity?
Environment
AppControl: All Support Versions
Resolution
No. Rule activity can be viewed from Reports > Events, using the 'Rule Name' subtype. The time-frame can be changed using the 'Max Age' drop-down, and the result can be viewed in the console or exported to a CSV format. This would be a manual process that would need to be performed however often the data set is desired. Automation however would require the use of a third-party SIEM application.
Additional Information
Information on SIEM integration can be found on the User eXchange within the Events Integration Guides for each AppControl server version.