AppControl: Can Rule Activity Be Reported in Automation?
search cancel

AppControl: Can Rule Activity Be Reported in Automation?

book

Article ID: 290560

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Can the activity of software rules be reported on a time-frame basis, for example a monthly report of File Integrity Control rule activity?

Environment

AppControl: All Support Versions

Resolution

No.  Rule activity can be viewed from Reports > Events, using the 'Rule Name' subtype.  The time-frame can be changed using the 'Max Age' drop-down, and the result can be viewed in the console or exported to a CSV format.  This would be a manual process that would need to be performed however often the data set is desired.  Automation however would require the use of a third-party SIEM application.

Additional Information

Information on SIEM integration can be found on the User eXchange within the Events Integration Guides for each AppControl server version.