Carbon Black Protection
The JSA DSM for Carbon Black Protection receives logs from a Carbon Black Protection device.
The following table identifies the specifications for the Carbon Black Protection DSM:
Table 1: Carbon Black Protection DSM Specifications
Specification | Value |
---|---|
Manufacturer | Carbon Black |
DSM name | Carbon Black Protection |
RPM filename | |
Supported versions | 8.0.0, 8.1.0 |
Protocol | Syslog |
Event format | LEEF |
Recorded event types | Computer Management, Server Management, Session Management, Policy Management, Policy Enforcement, Internal Events, General Management, Discovery |
Automatically discovered? | Yes |
Includes identity? | Yes |
Includes custom properties? | No |
More information | https://www.carbonblack.com/products/carbon-black |
If automatic updates are not configured, download the most recent version of the following RPMs on your JSA console
DSMCommon RPM
Carbon Black Protection DSM RPM
Enable the Carbon Black Protection console to communicate with JSA.
If JSA does not automatically detect the log source, add a Carbon Black Protection log source on the JSA Console. The following table describes the parameters that require specific values for Carbon Black Protection event collection:
Table 2: Carbon Black Protection Log Source Parameters
Parameter
Value
Log source type
Carbon Black Protection
Log source identifier
IP address or host name for the log source
Protocol configuration
Syslog
Verify that Carbon Black Protection is configured correctly.
The following table provides a sample event message for the Carbon Black Protection DSM:
Table 3: Carbon Black Protection Sample Message Supported by the Carbon Black Protection Device
Event name
Low level category
Sample log message
Console user login
User login success
LEEF:1.0| Carbon_Black|Protection| 8.0.0.2141| Console_user_login| cat=Session Management sev=4 devTime=Mar 09 2017 18:32:14.360 UTC msg=User 'admin' logged in from 127.0.0.1 externalId=12345 src=127.0.0.1 usrName=admin dstHostName=hostname receivedTime=Mar 09 2017 18:32:14.360 UTC
Configuring Carbon Black Protection to Communicate with JSA
Enable the Carbon Black Protection console to communicate with JSA.
- Access the Carbon Black Protection console by entering the Carbon Black Protection server URL in your browser.
- On the login screen, enter your username and password. You must use a Carbon Black Protection account with Administrator or Power User privileges.
- From the top console menu, select System Configuration in the Administration section.
- On the System Configuration page, click on the Events tab.
- On the External Events Logging section, click Edit. Enter the JSA Event Collector IP address in the Syslog address field and enter 514 for the Syslog port field.
- Change the Syslog format to LEEF (Q1Labs).
- Check Syslog Enabled for Syslog output.
- Click Update to confirm the changes.