carbon black and sentinel

Soumya Banerjee 126 Reputation points
2022-01-27T09:23:09.107+00:00

How do I receive carbon black logs into sentinel without AWS S3 bucket . Is it possible ?

I want to send data from carbon black to adx for longer retention. We will separately send alerts from carbon black to another soar platform. But just for long time log retention, especially events, need to send through to adx. Is there a way to achieve it.

Azure Data Explorer
Azure Data Explorer
An Azure data analytics service for real-time analysis on large volumes of data streaming from sources including applications, websites, and internet of things devices.
507 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,057 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,541 Reputation points Microsoft Employee
    2022-01-28T00:06:08.74+00:00

    @Soumya Banerjee
    Thank you for your post!

    When it comes to integrating Carbon Black logs into Azure Sentinel, we only have the VMware Carbon Black Endpoint Standard (Preview) connector. Which'll allow you to ingest data using Azure Functions and the REST API. However, an AWS Access Key Id, AWS Secret Access Key, AWS S3 Bucket Name, and Folder Name in AWS S3 Bucket are required for using the Amazon S3 REST API.
    169153-image.png

    Additional Links:
    Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data
    Find your Microsoft Sentinel data connector

    As of right now, using the Carbon Black Endpoint Standard (Preview) connector without an AWS S3 bucket isn't possible. However, if you'd like to be able to use it without an AWS S3 bucket, I'd recommend leveraging our User Voice forum and creating a feature request, so our engineering team can look into implementing this. I've also created an internal feature request, so our engineering team is aware of this as well.

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.