EDR: What Data is Sent Over CB Event Forwarder?
book
Article ID: 291088
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
What data is sent over CB Event Forwarder to the SIEM?
Environment
- EDR: All Versions
- CB Event Forwarder: All Supported Versions
Resolution
Setting | Default Value | Optional Values | Description | Associated CB.Conf Setting |
---|
audit_log |
|
|
- audit.log.useractivity
- audit.log.liveresponse
- audit.log.isolation
- audit.log.banning
|
- EnableExtendedApiAuditLogging=true
- EnableAuditLogsToEvents=true
|
api_token |
|
|
- Additional info from the REST API
|
|
remove_from_output |
|
|
- Prevents this field from causing issues with QRadar and Splunk
|
|
events_watchlist |
|
- watchlist.hit.process
- watchlist.hit.binary
- watchlist.storage.hit.process
- watchlist.storage.hit.binary
|
|
|
events_feed |
|
- feed.ingress.hit.process
- feed.ingress.hit.binary
- feed.ingress.hit.host
- feed.storage.hit.process
- feed.storage.hit.binary
- feed.query.hit.process
- feed.query.hit.binary
|
|
|
events_alert |
|
- alert.watchlist.hit.ingress.process
- alert.wtachlist.hit.ingress.binary
- alert.watchlist.hit.ingress.host
- alert.watchlist.hit.query.process
- alert.watchlist.hit.query.binary
|
|
|
events_binary_observed |
|
- binaryinfo.observed
- binaryinfo.host.observed
- binaryinfo.group.observed
|
|
|
events_binary_upload |
|
|
|
|
- use_raw_sensor_exchange
- events_raw_sensor
|
|
- ingress.event.process
- ingress.event.procstart
- ingress.event.netconn
- ingress.event.procend
- ingress.event.childproc
- ingress.event.moduleload
- ingress.event.module
- ingress.event.filemod
- ingress.event.regmod
- ingress.event.tamper
- ingress.event.crossprocopen
- ingress.event.remotethread
- ingress.event.processblock
- ingress.event.emetmitigation
|
- Raw Sensor (endpoint) Events
|
- EnableRawSensorDataBroadcast=true
|
Additional Information
- Enabling the "events_raw_sensor" setting can create a very high load and consume a Splunk license.
- If the "events_raw_sensor" feature causes performance issues on a Cloud instance it will be disabled and the contact on record will be notified.
- For a description of the events being sent look here
Feedback
thumb_up
Yes
thumb_down
No