icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Add-On- Endpoint Standard VMware Carbon Black Cloud
SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_204.tgz) 9414b67ffb5fb40c821ce943923a55f598603fa8d1870f50bc7aaeb61eb235b9 SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_202.tgz) 209704c06821af882deeb6a86c29bd88ecf0dd4358f0c4df073203d380617e94 SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_201.tgz) 5b237d98ba4e97b2445aeda2a9782bec9c802dc626c31617e1940f3c5d116f47 SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_200.tgz) ed2d928c0cae7898f955aafaf45fa948d88b302d43e150300dce54cfb7a69e90 SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_102.tgz) 5e127460f348719df57faeb240d82ec79de6f4d9ef35cc2c1fec31c7ca1fe742 SHA256 checksum (add-on-endpoint-standard-vmware-carbon-black-cloud_100.tgz) 85fa7611aad3aebe9f539e836bea7f437ab2486c02bc55c1b540fbc264664bab
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Add-On- Endpoint Standard VMware Carbon Black Cloud

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
As of January 31st, 2022 the APIs the app is consuming will be decomissioned causing some features to no longer function.
This app is no longer supported. Migrate to the VMware Carbon Black Cloud App for Splunk (https://splunkbase.splunk.com/app/5332/).

The Carbon Black Cloud Endpoint Standard Add-On for Splunk ingests notifications from Carbon Black Cloud into Splunk.

The Carbon Black Developer Network is proud to announce the second major public release of our Cb Defense Add-On for splunk.
This add-on is available for download now from Splunkbase and integrates
Splunk with your Cb Defense console, forwarding alerts from Cb Defense right into your Splunk instance.

This add-on is now compatible with both Splunk on-premise and Splunk cloud.

Requirements

This Add-On requires Cb Defense and Splunk version 6.6 or above.

No additional hardware requirements are necessary for running this Add-On above the standard requirements for both
Carbon Black and Splunk.

Getting Started

The App can be downloaded from Splunkbase, and then manually installed on a Splunk instance - or installed directly from within the Splunk UI by logging into Splunkbase and searching for the CB Defense Add-On for Splunk.

Once the Cb Defense Add-On for Splunk is installed, then you must configure it to connect to your Cb Defense server.
This is done by generating a "SIEM" connector key in the Cb Defense console. For information on how to generate API keys,
see the Cb Developer Network.
Ensure that your new Connector key is of type "SIEM".

Next, add "notification" rules to your Cb Defense server. Navigate to the "Settings -> Notifications" page and
click the "Add Notification" button. Make sure to add the connector key name you set up above into the list of
subscribed connectors in the text box at the bottom of the notification rule dialog box.

If you are working from a Splunk instance with a UI you can use the web-UI to configure the Add-on quite simply.
See below for instructions on how to configure the Add-on from the CLI - for instance when deploying to a forwarder.

To configure the Cb Defense Add-on for Splunk to connect to your Cb Defense server:

GUI Configuration

  1. Start the Cb Defense Add-on in Splunk
  2. Go to the "Inputs" tab - "Create new input" page and fill in the following fields:
    1. Enter the API hostname for your Cb Defense instance in the url field. See information on which URL to use here.
    2. Set apikey to your API key and the connector ID to your connector ID
    3. Set "name" to anything (for example "cbdefense")
    4. Set "interval" to 60 seconds (the polling interval of the Cb Defense notifications API)
    5. Set "index" to whatever Splunk index you'd like the Add-On to place Cb Defense events into

The 2.X Add-on for Splunk supports as many rest-inputs as a user desires. If you would like to integrate with multiple Cb Defense Servers/Connectors simply define multiple inputs.

The Cb Defense Add-On for Splunk uses Splunk’s encrypted credential storage facility to store the API token for your Cb Defense server, so the API key is stored securely on the Splunk server.

CLI Configuration

The Cb Defense Add-on for Splunk can also be configured through the CLI:

1) Manually install the Add-on, restart Splunk

2) Create a $SPLUNK_HOME/etc/apps/TA-Cb_Defense/local/inputs.conf like this:

```
[carbonblack_defense://<inputname>]
cb_defense_api_url = <ip or hostname of CB Defense> 
interval = <Interval to poll the notifications API at > 
siem_api_key = <API KEY> 
siem_connector_id = <connector ID>
```

Once again, you can define multiple stanzas in the inputs.conf to integrate with multiple Cb Defense Servers/Connectors.

Release Notes

Version 2.0.4
Aug. 22, 2019

Updated to re-enable support for Splunk Cloud

Version 2.0.2
Sept. 19, 2018

Updates to props.conf and transforms.conf.

Version 2.0.1
March 6, 2018

2.0.1: Updated to support multiple inputs from CbDefense.

When upgrading from the 1.0X versions of this Add-on please uninstall the Add-on first as per these instructions:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Managingappobjects#Uninstall_an_app_or_add-on

Version 2.0.0
March 2, 2018

2.0.0: Updated to support multiple inputs from CbDefense.

Version 1.0.2
Oct. 10, 2017

Add proxy support

Version 1.0.0
April 12, 2017

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.