ASIM File Event Parser for VMware Carbon Black Cloud

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index


Parser Information

Property Value
Parser Name ASimFileEventVMwareCarbonBlackCloud
Built-in Parser _ASim_FileEvent_VMwareCarbonBlackCloud
Schema FileEvent
Schema Version 0.2.1
Parser Type 🔌 Source (product-specific)
Product VMware Carbon Black Cloud
Parser Version 0.1.1 (version history)
Last Updated Oct 10, 2023
Unifying Parser ASimFileEvent
Source File Parsers\ASimFileEvent\Parsers\ASimFileEventVMwareCarbonBlackCloud.yaml

Description

This ASIM parser supports normalizing VMware Carbon Black Cloud logs to the ASIM File Event normalized schema. VMware Carbon Black Cloud events are captured through VMware Carbon Black Cloud data connector which ingests Carbon Black Audit, Notification and Event data into Microsoft Sentinel through the REST API.

Source Tables

This parser reads from the following tables:

Table Transformations Ingestion API Lake-Only
CarbonBlackEvents_CL 🔶 ? ?

Parameters

Name Type Default
disabled bool False

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index