Overview

The Carbon Black integration uses the Carbon Black Cloud API to ingest:

  • Alerts from Endpoint Standard, Enterprise EDR, and Audit & Remediation
  • Process and network event search results
  • Audit log entries for console actions

Prerequisites

  • A Carbon Black Cloud tenant.
  • The Org Key and API base URL for your region (visible under Settings → API Access).
  • Permission to create API access levels and API keys.

Step 1: Create an API access level

  1. Sign in to the Carbon Black Cloud Console.
  2. Go to Settings → API Access → Access Levels → Add Access Level.
  3. Name it atatus-siem and grant the following read permissions:
    • org.alertsRead
    • org.auditsRead
    • org.search.eventsRead
  4. Save the access level.

Step 2: Create an API key

  1. Still under Settings → API Access, open the API Keys tab and click Add API Key.
  2. Name it atatus-siem, set Access Level Type to Custom, and select the access level created above.
  3. Click Save, then copy the API ID and API Secret Key.
  4. From the API Access landing page, copy your Org Key and the API URL (for example, https://defense-prod05.conferdeploy.net).

Step 3: Connect Carbon Black in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Carbon Black card and click Connect.
  3. Fill in the form:
Field Description Example
API URL Carbon Black Cloud API base URL for your region. https://defense-prod05.conferdeploy.net
Org Key Carbon Black organization key. ABCD1234
API ID API key ID from Step 2. ABCDEF1234
API Secret Key API secret key from Step 2. ••••••••
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Carbon Black card shows Configured.
  • Alerts and audit events appear in Security → Cloud SIEM → Audit Logs → Events with source carbon_black.