Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Data source

Collector service

Optional

Flattening details

Source

Service

  • No

Flattening steps

Vendor setup

There are some steps you need to follow in order to set up this collector:

  1. Log in with your credentials to the Carbon Black console.

    Image RemovedImage Added
  2. Note your ORg Key on the top-left of the console.

  3. Go to Settings → API Access.

  4. Select the Access Level tab.

  5. Click on Add Access Level on the top-right.

  6. Give it a unique name and a description.

  7. Scroll down in the table below and look for the Event forwarding category. Mark the columns as the image below and click Save.

    Image RemovedImage Added
  8. Select the API Keys tab.

  9. Click on Add API Key.

  10. Give it a unique name and the appropriate access levels. Select Custom so you can choose the Access Level you created before. Note - Choose a name to clearly distinguish the API from your other API Keys. You can also add Authorized IP addresses and a description to differentiate among other APIs.

  11. Click Save and your credentials will display.

  12. You can view your credentials by opening the Actions drop-down and selecting API Credentials.

  13. Create your forwarder using the following API. A successful creation will add a healthcheck.json file to your event folder in your S3 bucket.

  14. Update your config.yalm with the appropriate values, including the AWS region and SQS qeue_name.

...