Carbon Black Cloud: Getting Started With the Data Forwarder
search cancel

Carbon Black Cloud: Getting Started With the Data Forwarder

book

Article ID: 292124

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

How to get started with and best practices for the Carbon Black Cloud Data Forwarder. 

Environment

  • Carbon Black Cloud Console: All Versions

Resolution

Setup Overview:
  1. Decide on a use case and necessary Event Type for the Data Forwarder, such as Alert triage, SIEM integration, or watchlist reporting.
    • Alert: All available Alerts.
    • Endpoint Event: All available endpoint telemetry.
    • Watchlist Hit: All available Watchlist hits. 
  2. Configure your AWS S3 Bucket or Azure Blob Storage to receive data from Carbon Black Cloud.
  3. Add a Data Forwarder in the Carbon Black Cloud Console.
    Tip: If using the Endpoint Event forwarder type, there are three methods of configuring which data is sent.
  4. Fetch the forwarded data from the destination or connect other tools to process the data, including SIEM solutions like Splunk, QRadar, or ServiceNow.
Key Resources for Custom Query Data Filters: Key Resources for API:

Additional Information