Skip to main content
Warning
This app is archived. App archiving documentation
VMware Carbon Black EDR On-Prem App app icon

VMware Carbon Black EDR On-Prem App

The Carbon Black EDR App for Splunk allows administrators to leverage the industry's leading EDR solution to see, detect and take action upon endpoint activity from directly within Splunk. Once installed, the App will allow administrators to access many of the powerful features of Carbon Black, such as process and binary searches from within and in conjunction with Splunk.Built by Carbon Black Developer Network
splunk product badge

Default Version 2.2.0

March 17, 2021

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

Rating
5
(5)

Log in to rate this app

Support
Archived App

The Carbon Black EDR App for Splunk allows administrators to leverage the industry's leading EDR solution to see, detect and take action upon endpoint activity from directly within Splunk. Once installed, the App will allow administrators to access many of the powerful features of Carbon Black, such as process and binary searches from within and in conjunction with Splunk. When used along side Splunk's Enterprise Security, the Carbon Black EDR App for Splunk also provides Adaptive Response Actions to take action automatically based on the result of Correlation Searches and on an ad-hoc basis on Notable Events surfaced within Splunk ES. Published by the Carbon Black Developer Network http://developer.carbonblack.com