|
| 1 | +## Overview |
| 2 | + |
| 3 | +[Carbon Black Cloud][1] is a cloud-native endpoint protection platform (EPP) that provides what you need to secure your endpoints using a single, lightweight agent and an easy-to-use console. |
| 4 | + |
| 5 | +Integrate Carbon Black Cloud with Datadog to gain insights into Alerts, Audit Logs, Auth Events, Endpoint Events and Watchlist Hits using pre-built dashboard visualizations. Additionally, integration includes ready-to-use Cloud SIEM detection rules for enhanced monitoring and security. |
| 6 | + |
| 7 | + |
| 8 | +## Setup |
| 9 | + |
| 10 | +### Configure AWS S3 Bucket |
| 11 | + |
| 12 | +- Please refer the [Use AWS S3 guide][2]. |
| 13 | + |
| 14 | +### Configure Datadog Forwarder |
| 15 | + |
| 16 | +- Please refer the [Datadog Forwarder][3] |
| 17 | + |
| 18 | +### Configure Carbon Black Cloud Data Forwarder |
| 19 | + |
| 20 | +1. Login to **Carbon Black Cloud console** as a Super Admin privileges. |
| 21 | +2. On the left navigation pane, click **Settings > Data Forwarders**. |
| 22 | +3. Click **Add Forwarder**. |
| 23 | +4. Enter a unique name for the Data Forwarder. |
| 24 | +5. Select a **Type** from the dropdown list. |
| 25 | +6. Select an **AWS S3** option from the provider dropdown list. |
| 26 | +7. Enter the **S3 bucket** name you have created on AWS. |
| 27 | +8. For the **S3 prefix**, please use the base prefix **carbonblackcloud** for all types. The following specific prefixes should be applied according to the type: |
| 28 | + 1. For **Alert** type, use the prefix: `carbonblackcloud-alerts` |
| 29 | + 2. For **Audit log** type, use the prefix: `carbonblackcloud-audit-logs` |
| 30 | + 2. For **Auth event** type, use the prefix: `carbonblackcloud-auth-events` |
| 31 | + 3. For **Endpoint event** types, use the prefix: `carbonblackcloud-endpoint-events` |
| 32 | + 4. For **Watchlist Hit** type, use the prefix: `carbonblackcloud-watchlist-hits` |
| 33 | +8. Set the **forwarder status** to `On`. |
| 34 | +9. To apply the changes, click **Save**. |
| 35 | + |
| 36 | +## Data Collected |
| 37 | + |
| 38 | +### Logs |
| 39 | + |
| 40 | +The Carbon Black Cloud integration collects `Alert`, `Audit log`, `Auth event`, `Endpoint event`, and `Watchlist hit` logs. |
| 41 | + |
| 42 | +### Metrics |
| 43 | + |
| 44 | +The Carbon Black Cloud integration does not include any metrics. |
| 45 | + |
| 46 | +### Events |
| 47 | + |
| 48 | +The Carbon Black Cloud integration does not include any events. |
| 49 | + |
| 50 | +## Support |
| 51 | + |
| 52 | +For any further assistance, contact [Datadog support][4]. |
| 53 | + |
| 54 | + |
| 55 | +[1]: https://www.broadcom.com/products/carbon-black/threat-prevention/carbon-black-cloud |
| 56 | +[2]: https://developer.carbonblack.com/reference/carbon-black-cloud/integrations/data-forwarder/quick-setup/#option-1-use-aws-s3 |
| 57 | +[3]: https://docs.datadoghq.com/logs/guide/forwarder/?tab=manual |
| 58 | +[4]: https://docs.datadoghq.com/help/ |
0 commit comments