Overview
The Carbon Black integration uses the Carbon Black Cloud API to ingest:
- Alerts from Endpoint Standard, Enterprise EDR, and Audit & Remediation
- Process and network event search results
- Audit log entries for console actions
Prerequisites
- A Carbon Black Cloud tenant.
- The Org Key and API base URL for your region (visible under Settings → API Access).
- Permission to create API access levels and API keys.
Step 1: Create an API access level
- Sign in to the Carbon Black Cloud Console.
- Go to Settings → API Access → Access Levels → Add Access Level.
- Name it
atatus-siemand grant the following read permissions:org.alerts— Readorg.audits— Readorg.search.events— Read
- Save the access level.
Step 2: Create an API key
- Still under Settings → API Access, open the API Keys tab and click Add API Key.
- Name it
atatus-siem, set Access Level Type to Custom, and select the access level created above. - Click Save, then copy the API ID and API Secret Key.
- From the API Access landing page, copy your Org Key and the API URL (for example,
https://defense-prod05.conferdeploy.net).
Step 3: Connect Carbon Black in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Carbon Black card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| API URL | Carbon Black Cloud API base URL for your region. | https://defense-prod05.conferdeploy.net |
| Org Key | Carbon Black organization key. | ABCD1234 |
| API ID | API key ID from Step 2. | ABCDEF1234 |
| API Secret Key | API secret key from Step 2. | •••••••• |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Carbon Black card shows Configured.
- Alerts and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source
carbon_black.
+1-415-800-4104