CarbonBlack_Watchlist_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: Connector definition

Column Name Type
CreateTime string
DeviceExternalIp string
DeviceId string
DeviceInternalIp string
DeviceName string
DeviceOs string
IocHit string
IocId string
OrgKey string
ParentCmdline string
ParentGuid string
ParentHash string
ParentPath string
ParentPid string
ParentPublisher string
ParentReputation string
ParentUsername string
ProcessCmdline string
ProcessGuid string
ProcessHash string
ProcessPath string
ProcessPid string
ProcessPublisher string
ProcessReputation string
ProcessUsername string
ReportId string
ReportName string
ReportTags string
Schema string
Severity string
TimeGenerated datetime
Watchlists string
WatchlistsType string

Solutions (1)

This table is used by the following solutions:

Connectors (2)

This table is ingested by the following connectors:

Connector Selection Criteria
VMware Carbon Black Cloud via AWS S3
VMware Carbon Black Cloud via AWS S3 (via Codeless Connector Framework)


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index