Carbon Black 샘플 이벤트 메시지
이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.
중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.
Syslog 프로토콜을 사용할 때의 Carbon Black 샘플 메시지
샘플 1: 다음 샘플 이벤트 메시지는 프로세스와 일치하는 감시 목록 조회를 표시합니다.
LEEF:1.0|CB|CB|5.1|alert.watchlist.hit.query.process|alert_severity=50.625 alert_type=watchlist.hit.query.process alliance_score_srstrust=-100 cb_server=None childproc_count=1 comms_ip=192.168.230.5 computer_name=W7-LOW created_time=2015-10-29T04:33:06.713157Z crossproc_count=0 feed_id=-1 feed_name=My Watchlists feed_rating=3.0 filemod_count=0 group=Default Group hostname=W7-LOW interface_ip=192.168.230.5 ioc_attr={"highlights": ["PREPREPREacrord32.exePOSTPOSTPOST"]} ioc_confidence=0.5 ioc_type=query md5=AD7B9C14083B52BC532FBA5948342B98 modload_count=14 netconn_count=0 os_type=windows process_guid=00000016-0000-0804-01d1-17153be2e8cd process_name=cmd.exe process_path=c:\windows\system32\cmd.exe regmod_count=0 report_score=75 segment_id=1 sensor_criticality=3.0 sensor_id=22 status=Unresolved timestamp=1446093201.95 type=alert.watchlist.hit.query.process unique_id=3ee47556-3e8e-4232-b975-30ba7fbf0037 username=BIT9SEAD\user10 watchlist_id=11 watchlist_name=Unusual Parents
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 필드 이름 또는 값 |
|---|---|
| 이벤트 ID | alert.watchlist.hit.query.process |
| 이벤트 카테고리 | 이 DSM의 경우 QRadar 의 값은 항상 CarbonBlack 입니다. |
| 소스 IP | interface_ip |
| username | username |
| 디바이스 시간 | created_time |