Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VMware Carbon Black Cloud (using Function app) data connector not ingesting full three type of logs - Sentinel #10440

Open
laylavo opened this issue May 4, 2024 · 6 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@laylavo
Copy link

laylavo commented May 4, 2024

Describe the bug
A clear and concise description of what the bug is.

In VMware Carbon Black Cloud data connector, there are three types of logs: CarbonBlackEvents_CL, CarbonBlackAuditLogs_CL, CarbonBlackNotifications_CL

After deploy Azure Function app successfully, only one CarbonBlackAuditLogs_CL appears in LAW:

To Reproduce
Steps to reproduce the behavior:

  • Deploy Azure Function App
  • In Carbon Black Log Types, I have type: Audit, Events, Alert
  • The deployment successful.
  • Check the Function Apps details, there is no errors

Please advice!

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label May 6, 2024
@v-sudkharat
Copy link
Contributor

Hi @laylavo, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 15-05-2024. Thanks!

@laylavo
Copy link
Author

laylavo commented May 15, 2024

hi @sudkharat, may i know is there any updates ?

@v-sudkharat
Copy link
Contributor

Hey @laylavo, We need more time to check and investigate into this issue. Thanks!

@laylavo
Copy link
Author

laylavo commented May 15, 2024

may i know the deadline because my cx pushes to update. Thanks

@v-sudkharat
Copy link
Contributor

Sure, we will share update you by- 23-05-2024. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @laylavo, The CarbonBlackNotifications_CL is got deprecated as per Document and there is new Alert API to get Alert information. The API required the CarbonBlackOrgKey filed configured in the Environment Variable section of Function App. So kindly check on the below Highlighted parameter screenshot and fetch org_key details screenshot: -

image

org_key in console side:-

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

3 participants