carbonblack/cb-event-forwarder
Subscribe to raw VMware Carbon Black EDR event feed and forward to another system, such as Splunk.
JavaScriptNOASSERTION
Issues
- 0
Format of syslog is not RFC Compliant
#236 opened by jjfallete - 4
- 0
Request: Include comms_ip in all telemetry
#226 opened by vector-sec - 7
- 0
Correct Service Permissions
#224 opened by jjfallete - 1
Event filtering for raw CB EdR event logs
#220 opened by davial1 - 0
init.d upgrade issues
#165 opened by zacharyestep - 2
Log rolling
#171 opened by LDNail - 0
log rolling issue
#170 opened by LDNail - 6
3.7.4-1 CentOS 7 syslog only logs a number
#216 opened by ethansutcliffe - 0
parsing "protobuf" files into Json format
#215 opened by YuvalNaor - 0
- 2
- 0
- 0
- 0
Minor issue with double equal character in cb-event-forwarder.example.ini/conf
#206 opened by m4ticode - 0
permissions issue
#195 opened by Orpere - 0
Unable to configure syslog with tcp protocol via WebUI
#191 opened by r-nd03 - 1
- 8
Failed Dependency on Fresh CB Install
#146 opened by pilot006 - 0
RHEL7 rpm not contained in the repository
#164 opened by ThePhilderbeast - 1
cb-event-forwarder not available for debian distro
#161 opened by kaiiyer - 1
Event Forwarder Does not appear to include SHA256 Values for some fields
#162 opened by robsmallridge - 1
cb event forwarder not sending event
#155 opened by austin-lai - 2
Failed dependencies On Redhat 7
#152 opened by nealmadhu - 0
SPLUNK HEC - Index Acknowledgement
#147 opened by zacharyestep - 1
Multiple instances of cb-event-forwarder
#148 opened by aditi03 - 1
Installation issues with CentOS 7
#149 opened by aremai - 1
CentOS 7 installation Failed
#150 opened by King-Prakatheesh - 3
RHEL7 rpm not contained in the repositry
#145 opened by ThePhilderbeast - 1
Filtering by actions
#142 opened by chilichzfrito - 4
need a unit file for systemd
#136 opened by lunardial - 1
Forward events from Cb Resonse Cloud to Splunk Cloud
#141 opened by rzzldzzl - 12
gRPC output
#134 opened by NeQuissimus - 4
kafka output type missing in config.go
#133 opened by dstruck - 0
- 1
Investigate persistent queues for certain event types
#125 opened by jgarman - 1
- 1
Change default segment ID from "1" to "0"
#126 opened by jgarman - 2
Make output options more modular
#109 opened by mtmcgrew - 1
using use_raw_sensor_exchange does not work
#116 opened by mtmcgrew - 2
cb event forwarder & splunk
#121 opened by dnamza - 0
RabbitMQ TLS connections don't work
#108 opened by n2N8Z - 0
Dropped event count not updated
#103 opened by n2N8Z - 2
local/remote IP addresses appear to be flipped when emitting "inbound" netconns
#120 opened by jgarman - 5
Missing fields in childproc messages
#107 opened by jgajek - 1
events_raw_sensor should default to 0 instead of ALL
#119 opened by dbrouss - 2
Connected state not updated
#102 opened by n2N8Z - 1
"too many arguments" build error
#104 opened by mtmcgrew - 1
"Report name" is not available in Qradar logs.
#97 opened by kzaman001