Carbon Black Logs (Beta)

Connecting Carbon Black logs in your Panther Console

Overview

Panther supports the following methods of ingesting logs from Carbon Black:

  • Carbon Black Audit Logs API: Panther can fetch Carbon Black audit logs by directly querying the the Carbon Black API.

    Carbon Black Audit log ingestion is in open beta starting with Panther version 1.78, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

  • Carbon Black Data Streaming: Panther can ingest Carbon Black data regarding alerts, endpoint events, and watchlist hits using Carbon Black's data streaming feature via AWS S3.

    Carbon Black Data Streaming ingestion is in open beta starting with Panther version 1.86, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

How to onboard Carbon Black Audit logs to Panther

To set up Carbon Black as a log source in Panther, you will create a new log source in Panther using a Carbon Black API key.

Step 1: Generate a Carbon Black API key

  1. Log in to your Carbon Black instance.

  2. Click Settings > API Access, then Add API Key.

  3. Enter a name, and set Access Level Type to API.

  4. Optionally fill in the Authorized IP Address section to restrict access to only Panther's IP address.

  5. Copy the API ID and API Secret Key and store them in a secure location, as you will need these values in the next step.

Step 2: Create a new Carbon Black Audit Logs source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Carbon Black Audit Logs," then click its tile.

  4. In the slide-out panel, click Start Setup.

  5. On the next screen, enter a descriptive name for the source, such as My Carbon Black Audit logs.

  6. Click Setup.

  7. On the Set Credentials page, fill in the form:

    1. Carbon Black Domain: Enter the URL of your Carbon Black domain.

    2. API ID: Enter the Carbon Black API ID generated in Step 1.

    3. API Secret Key: Enter the API Secret Key generated in Step 1.

  8. Click Setup. You will be directed to a success screen:

    The success screen reads, "Everything looks good! Panther will now automatically pull & process logs from your account"
    • You can optionally enable one or more Detection Packs.

    • The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.

      The "Trigger an alert when no events are processed" toggle is set to YES. The "How long should Panther wait before it sends you an alert that no events have been processed" setting is set to 1 Day

How to onboard Carbon Black Data Streaming logs to Panther

To configure Carbon Black log streaming for ingestion in Panther, you will first set up Data Forwarders in Carbon Black, then create a Carbon Black Data Streaming source in Panther.

Step 1: Set up Carbon Black Data Forwarders to an S3 bucket

After completing this process, your Data Forwarders will look similar to the below:

Three rows contain various information about Data Forwarders, including the status, name, type, destination, updated time, and actions.

Step 2: Create a new Carbon Black Data Streaming source in Panther

  1. In the left-hand navigation bar of the Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Carbon Black," then click the Carbon Black Data Streaming tile.

    • In the slide-out panel, the Transport Mechanism dropdown in the upper-right corner will be pre-populated with the AWS S3 Bucket option.

      In the search box is "carbon black streaming," and one of the results, a box titled "Carbon Black Data Streaming," is circled.
  4. Click Start Setup.

  5. Follow Panther's instructions for configuring an S3 Source, with the below modifications:

    1. On the Basic Info page, click Configure Prefixes & Schemas (Optional).

    2. For each Data Forwarder you created in Step 1 of this process, create an S3 Prefix and schema pair. If you are using all three log types, this will look like:

      A form titled "S3 Prefixes & Schemas" shows three pairs of "S3 Prefix" and "Schemas - Optional" fields.
    3. Click Apply Changes.

Audit Log source log types

Required fields in the schema are listed as "required: true" just below the "name" field.

These are audit logs of events in a Carbon Black tenant. For more information, see the Carbon Black Audit Log Events documentation.

CarbonBlack.Audit

Data Streaming source log types

For more information, see the Carbon Black Data Forwarder schema documentation.

Required fields in the schema are listed as "required: true" just below the "name" field.

CarbonBlack.AlertV2

CarbonBlack.EndpointEvent

CarbonBlack.WatchlistHit

Last updated

Was this helpful?