Document toolboxDocument toolbox

edr.carbonblack

Introduction

The tags beginning with edr.carbonblack identify events generated by VMware Carbon Black.

Tag structure

The full tag must have 3 levels. The first two are fixed as edr.carbonblack. The third level identifies the type of events sent.

Technology

Brand

Type

Technology

Brand

Type

edr

carbonblack

  • alert

  • binary

  • feed

  • ingress

  • watchlist

Therefore, the valid tags and tables include:

  • edr.carbonblack.alert

  • edr.carbonblack.binary

  • edr.carbonblack.feed

  • edr.carbonblack.ingress

  • edr.carbonblack.watchlist

How is the data sent to Devo?

You can forward logs generated by VMware Carbon Black using any Syslog drain (for example, Syslog-ng) or through Devo Relay.