Send Carbon Black EDR Logs to the Sensor
Before configuring the log collection, you must have the IP address of the USM Anywhere Sensor. To send log data from Carbon Black EDR to USM Anywhere- Install and configure the cb-event-forwarder. See the Carbon Black Event Forwarder Quickstart Guide for instructions. Events exported from Carbon Black Event Forwarder can be in JavaScript Object Notation (JSON) or Log Event Extended Format (LEEF) format.
-
Modify the /etc/cb/integrations/event-forwarder/cb-event-forwarder.conf file, include the following item:
udpout=<USM-Anywhere-Sensor-IP-Address>:514
Assign Assets to the BlueApp
To help BlueApp for Carbon Black EDR identify the relevant logs, you must associate this app with the asset that is forwarding the logs. To assign assets to the BlueApp- In USM Anywhere, go to Data Sources > BlueApps.
- Click the Available Apps tab.
- Search for the BlueApp, and then click the tile.
- Click Assign Asset.
- Search for your asset using its name or IP address, and then click Assign.
- If your asset is not in USM Anywhere, click Create Asset to add it.
- Select the method that the USM Anywhere Sensor should use to collect logs from your asset. Syslog is the default method, but USM Anywhere can also collect logs from an Amazon S3 bucket or Amazon CloudWatch.
-
In the Format field, click the
icon and select JSON from the drop-down. Events exported from Carbon Black Event Forwarder are in a normalized JSON format; therefore you must set the Format field to JSON.