AgileBlue can collect alert and event logs from VMware Carbon Black Cloud by leveraging the Carbon Black Cloud REST APIs.
Supported Platform Version
- Alerts API v6 and newer
- Audit Log Events v3 and newer
- Vulnerability Assessment v1 and newer
Setup Process
- Log in to Carbon Black Cloud and navigate to Settings > API Access
- Select Add API Key
- Apply a unique name and description to the API Key
- Select the access level types based on the table below
Data Stream
Access Level and Permissions
Audit
API
Alert
Custom orgs.alerts (Read)
Asset Vulnerability Summary
Custom vulnerabilityAssessment.data (Read)
- Click Save to apply these updates
- Securely send the following values back to AgileBlue Support:
- Hostname
- This is your Carbon Black Cloud console Hostname – you can provide the full web address for your Carbon Black console dashboard.
- Organization Key
- Custom API ID
- Custom API Secret Key
- API ID
- API Secret Key
- Hostname
Need Help?
AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400🚨