Table of Contents | ||||
---|---|---|---|---|
|
Overview
VMware Carbon Black Cloud Event Forwarder is a cloud-native endpoint, workload, and container protection platform that combines the intelligent system hardening and behavioral prevention needed to keep emerging threats at bay, using a single, easy-to-use console. By analyzing more than 1 trillion security events per day, VMware CBC proactively uncovers attackers’ behavior patterns and empowers defenders to detect and stop emerging attacks.
This Devo collector helps to extend CBC's rich analytics and response actions to the rest of our customers' security stack.
...
native endpoint security software that is designed to detect malicious behavior and help prevent malicious files from attacking an organization. It allows you to send data about alerts and events to an AWS S3 bucket where it can be reconfigured into other applications.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( |
|
Running environments |
|
Populated Devo events |
|
Flattening preprocessing |
|
...
Data source | Collector service | Optional | Flattening details |
---|---|---|---|
Source | Service |
| Flattening steps |
Vendor setup
There are some steps you need to follow in order to set up this collector:
Log in with your credentials to the Carbon Black console.
Note your ORg Key on the top-left of the console.
Go to Settings → API Access.
Select the Access Level tab.
Click on Add Access Level on the top-right.
Give it a unique name and a description.
Scroll down in the table below and look for the Event forwarding category. Mark the columns as the image below and click Save.
Select the API Keys tab.
Click on Add API Key.
Give it a unique name and the appropriate access levels. Select Custom so you can choose the Access Level you created before. Note - Choose a name to clearly distinguish the API from your other API Keys. You can also add Authorized IP addresses and a description to differentiate among other APIs.
Click Save and your credentials will display.
You can view your credentials by opening the Actions drop-down and selecting API Credentials.
Create your forwarder using the following API. A successful creation will add a healthcheck.json file to your event folder in your S3 bucket.
Update your config.yalm with the appropriate values, including the AWS region and SQS qeue_name.
Minimum configuration required for basic pulling
...