Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Carbon Black Bit9 Parity

 

To collect events, you must configure your Carbon Black Bit9 Parity device to forward syslog events in Log Event Extended Format (LEEF).

  1. Log in to the Carbon Black Bit9 Parity console with Administrator or PowerUser privileges.
  2. From the navigation menu on the left side of the console, select Administration >System Configuration.

    The System Configuration window is displayed.

  3. Click Server Status.

    The Server Status window is displayed.

  4. Click Edit.
  5. In the Syslog address field, type the IP address of your JSA console or Event Collector.
  6. From the Syslog format list, select LEEF (Q1Labs).
  7. Select the Syslog enabled check box.
  8. Click Update.

    The configuration is complete. The log source is added to JSA as Carbon Black Bit9 Parity events are automatically discovered. Events that are forwarded to JSA by Carbon Black Bit9 Parity are displayed on the Log Activity tab of JSA.

Configuring a Log Source For Carbon Black Bit9 Parity

JSA automatically discovers and creates a log source for syslog events from Carbon Black Bit9 Parity.

The following configuration steps are optional.

  1. Log in to JSA.
  2. Click the Admin tab.
  3. On the navigation menu, click Data Sources.
  4. Click the Log Sources icon.
  5. Click Add.
  6. In the Log Source Name field, type a name for your log source.
  7. In the Log Source Description field, type a description for the log source.
  8. From the Log Source Type list, select Bit9 Security Platform.
  9. Using the Protocol Configuration list, select Syslog.
  10. Configure the following values:

    Table 1: Syslog Parameters

    Parameter

    Description

    Log Source Identifier

    Type the IP address or host name for the log source as an identifier for events from your Carbon Black Bit9 Parity device.

  11. Click Save.
  12. On the Admin tab, click Deploy Changes.

    The configuration is complete.