Carbon Black
StandardCarbon Black for Logpoint SIEM allows you to monitor and identify threats in your organization using the Carbon Black data. Logpoint aggregates and normalizes event data from Carbon Black in the LEEF, JSON, or Syslog format.
Release Details
Enhancement
KB-23291
Added Syslog Collector based CarbonBlack log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
Bug Fix
KB-1055145411
An issue in the compiled normalizer CarbonBlackCompiledNormalizer where some Carbon Black logs were not properly normalized.
Installation
To install Carbon Black :
- Download the .pak file from the Download link above.
- Go to Settings >> System Settings from the navigation bar and click Applications .
- Click Import .
- Browse to the downloaded .pak file.
- Click Upload .
Past Releases
Carbon Black v5.1.0 ▾
Enhancements
KB-10527, KB-10582, KB-1057645411
Added a compiled normalizer CarbonblackJSONCompiledNormalizer to normalize the JSON events.
In the compiled normalizer CarbonBlackCompiledNormalizer, the field username has been parsed as the user and domain fields.
The taxonomy of the following fields has been changed to maintain consistency:
-
computertoworkstation -
starttostart_ts -
last_updatetolast_update_ts
Bug Fix
KB-1055145411
An issue in the compiled normalizer CarbonBlackCompiledNormalizer where some Carbon Black logs were not properly normalized.
Carbon Black v5.0.1 ▾
Enhancement
A minor update in the Carbon Black's normalizer for better signature handling.
Support
If you have any questions or require assistance, abc.local.com.
Comments
Article is closed for comments.