Carbon Black 샘플 이벤트 메시지

이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.

중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

Syslog 프로토콜을 사용할 때의 Carbon Black 샘플 메시지

샘플 1: 다음 샘플 이벤트 메시지는 프로세스와 일치하는 감시 목록 조회를 표시합니다.

LEEF:1.0|CB|CB|5.1|alert.watchlist.hit.query.process|alert_severity=50.625	alert_type=watchlist.hit.query.process	alliance_score_srstrust=-100	cb_server=None	childproc_count=1	comms_ip=192.168.230.5	computer_name=W7-LOW	created_time=2015-10-29T04:33:06.713157Z	crossproc_count=0	feed_id=-1	feed_name=My Watchlists	feed_rating=3.0	filemod_count=0	group=Default Group	hostname=W7-LOW	interface_ip=192.168.230.5	ioc_attr={"highlights": ["PREPREPREacrord32.exePOSTPOSTPOST"]}	ioc_confidence=0.5	ioc_type=query	md5=AD7B9C14083B52BC532FBA5948342B98	modload_count=14	netconn_count=0	os_type=windows	process_guid=00000016-0000-0804-01d1-17153be2e8cd	process_name=cmd.exe	process_path=c:\windows\system32\cmd.exe	regmod_count=0	report_score=75	segment_id=1	sensor_criticality=3.0	sensor_id=22	status=Unresolved	timestamp=1446093201.95	type=alert.watchlist.hit.query.process	unique_id=3ee47556-3e8e-4232-b975-30ba7fbf0037	username=BIT9SEAD\user10	watchlist_id=11	watchlist_name=Unusual Parents
표 1. Carbon Black 샘플 이벤트에서 강조표시된 값
QRadar 필드 이름 이벤트 페이로드에서 강조표시된 필드 이름 또는 값
이벤트 ID alert.watchlist.hit.query.process
이벤트 카테고리 이 DSM의 경우 QRadar 의 값은 항상 CarbonBlack 입니다.
소스 IP interface_ip
username username
디바이스 시간 created_time