Skip to content

Commit 99dd481

Browse files
authored
Carbon Black Inventory (#5883)
* Carbon Black Inventory * Update cid-redirects.json * changed the release date to avoid cnflicts
1 parent ae0bab7 commit 99dd481

File tree

6 files changed

+158
-0
lines changed

6 files changed

+158
-0
lines changed

blog-service/2025-10-08-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Carbon Black Inventory (Apps)
3+
image: https://help.sumologic.com/img/reuse/rss-image.jpg
4+
keywords:
5+
- apps
6+
- carbon-black-inventory
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Sumo Logic app for Carbon Black Inventory. This app offers you enhanced capabilities to identify risks and configuration gaps in your environment. [Learn more](/docs/integrations/saas-cloud/carbon-black-inventory/).

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2943,6 +2943,7 @@
29432943
"/cid/1108": "/docs/integrations/saas-cloud/trellix-mvision-epo",
29442944
"/cid/1110": "/docs/integrations/microsoft-azure/azure-security-microsoft-defender-for-identity",
29452945
"/docs/integrations/microsoft-azure/microsoft-defender-for-identity/": "/docs/integrations/microsoft-azure/azure-security-microsoft-defender-for-identity",
2946+
"/cid/1112": "/docs/integrations/saas-cloud/carbon-black-inventory/",
29462947
"/cid/1111": "/docs/integrations/microsoft-azure/azure-open-ai",
29472948
"/Cloud_SIEM_Enterprise": "/docs/cse",
29482949
"/Cloud_SIEM_Enterprise/Administration": "/docs/cse/administration",

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -146,6 +146,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
146146
| <img src={useBaseUrl('img/integrations/databases/cassandra.png')} alt="Thumbnail icon" width="50"/> | [Cassandra](https://cassandra.apache.org/) | Apps: <br/>- [Cassandra](/docs/integrations/databases/cassandra/) <br/>- [Cassandra - OpenTelemetry](/docs/integrations/databases/opentelemetry/cassandra-opentelemetry/) |
147147
| <img src={useBaseUrl('img/integrations/misc/catchpoint-logo.png')} alt="Thumbnail icon" width="50"/> | [Catchpoint](https://www.catchpoint.com/) | Partner integration: [Catchpoint](https://github.com/catchpoint/Integrations.SumoLogic/blob/main/README.md) |
148148
| <img src={useBaseUrl('img/send-data/cato-logo.png')} alt="Thumbnail icon" width="50"/> | [Cato Networks](https://www.catonetworks.com/) | App: [Cato Networks](/docs/integrations/saas-cloud/cato-networks/) <br/>Cloud SIEM integration: [Cato Networks](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/53e043b0-76e3-471a-84ec-0266a4f3b279.md) <br/>Collector: [Cato Networks Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cato-networks-source/) |
149+
| <img src={useBaseUrl('img/integrations/security-threat-detection/vmcarecb.png')} alt="Thumbnail icon" width="50"/> | Carbon Black Inventory | App: [Carbon Black Inventory](/docs/integrations/saas-cloud/carbon-black-inventory/) <br/>Collector: [Carbon Black Inventory Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cato-networks-source/) |
149150
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/censys.png')} alt="Thumbnail icon" width="75"/> | [Censys](https://censys.com/) | Automation integrations: <br/>- [Censys](/docs/platform-services/automation-service/app-central/integrations/censys/) <br/>- [Censys V2](/docs/platform-services/automation-service/app-central/integrations/censys-v2/) |
150151
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/certego.png')} alt="Thumbnail icon" width="75"/> | [Certego](https://www.certego.net/) | Automation integration: [Certego](/docs/platform-services/automation-service/app-central/integrations/certego/) |
151152
| <img src={useBaseUrl('img/send-data/chatgpt-compliance.png')} alt="Thumbnail icon" width="50"/> | [ChatGPT Compliance](https://chatgpt.com/) | Collector: [ChatGPT Compliance Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/chatgpt-compliance-source) |
Lines changed: 137 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,137 @@
1+
---
2+
id: carbon-black-inventory
3+
title: Carbon Black Inventory
4+
sidebar_label: Carbon Black Inventory
5+
description: The Sumo Logic app for Carbon Black Inventory enables security analysts identify risks and configuration gaps to improve endpoint hygiene, faster response, and stronger overall security.
6+
---
7+
8+
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
10+
<img src={useBaseUrl('img/integrations/security-threat-detection/vmcarecb.png')} alt="Carbon Black Inventory icon" width="90" />
11+
12+
The Sumo Logic app for Carbon Black Inventory offers comprehensive visibility into endpoint assets and their security posture across your environment. By consolidating key device data, including total device counts, compliance status, antivirus and sensor health, and vulnerability levels, the app enables security teams to quickly identify at-risk endpoints and configuration gaps.
13+
14+
Dedicated panels highlight quarantined devices, non-compliant endpoints, systems with passive or outdated sensors, and devices lacking recent antivirus scans, allowing you to efficiently monitor operational hygiene and security coverage. Visualizations by operating system, vulnerability severity, and geographic location provide valuable context for prioritizing patching and remediation.
15+
16+
By surfacing high-priority issues, such as stale endpoints, disabled firewalls, or devices located in embargoed regions, alongside a complete inventory summary, the Sumo Logic app for Carbon Black Inventory helps you maintain strong endpoint hygiene, reduce risk exposure, and support compliance initiatives. This unified view empowers teams to respond faster, improve device management, and strengthen security across the IT environment.
17+
18+
:::info
19+
This app includes [built-in monitors](#carbon-black-inventory-alerts). For details on creating custom monitors, refer to [Create monitors for Carbon Black Inventory app](#create-monitors-for-the-carbon-black-inventory-app).
20+
:::
21+
22+
## Log types
23+
24+
This app uses Sumo Logic’s [Carbon Black Inventory Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/carbon-black-inventory-source/) to collect device logs from the Carbon Black Inventory platform.
25+
26+
## Sample log message
27+
28+
<details>
29+
<summary>Device Log</summary>
30+
31+
```json
32+
{
33+
"id": 2008,
34+
"name": "Device-NotReporting",
35+
"os": "WINDOWS",
36+
"os_version": "Windows 7",
37+
"last_external_ip_address": "2.58.14.95",
38+
"quarantined": false,
39+
"compliance_status": "COMPLIANT",
40+
"host_based_firewall_status": "ENABLED",
41+
"av_status": [
42+
"AV_ACTIVE"
43+
],
44+
"sensor_pending_update": false,
45+
"sensor_out_of_date": false,
46+
"passive_mode": false,
47+
"sensor_states": [
48+
"LIVE_RESPONSE_NOT_RUNNING"
49+
],
50+
"av_last_scan_time": "2025-09-25T19:11:38.742Z",
51+
"vulnerability_score": 2.5,
52+
"vulnerability_severity": "LOW",
53+
"last_contact_time": "2025-09-25T19:11:38.742Z",
54+
"last_reported_time": "2025-09-25T19:11:38.742Z",
55+
"registered_time": "2025-09-25T19:11:38.742Z"
56+
}
57+
```
58+
</details>
59+
60+
## Sample queries
61+
62+
```sql title="Total Devices"
63+
_sourceCategory="Labs/CarbonBlackInventory"
64+
| json "id", "quarantined", "compliance_status", "host_based_firewall_status", "av_status", "sensor_pending_update", "os", "vulnerability_severity", "last_external_ip_address", "sensor_states", "passive_mode", "name", "sensor_out_of_date", "last_reported_time", "last_contact_time", "registered_time", "vulnerability_score", "os_version", "av_last_scan_time" as id, quarantined, compliance_status, host_based_firewall_status, av_status_list, sensor_pending_update, os, vulnerability_severity, last_external_ip_address, sensor_states_list, passive_mode, name, sensor_out_of_date, last_reported_time, last_contact_time, registered_time, vulnerability_score, os_version, av_last_scan_time nodrop
65+
66+
| where os matches "*"
67+
| where vulnerability_severity matches "*"
68+
69+
| count by id
70+
| count
71+
```
72+
73+
## Collection configuration and app installation
74+
75+
import CollectionConfiguration from '../../reuse/apps/collection-configuration.md';
76+
77+
<CollectionConfiguration/>
78+
79+
:::important
80+
Use the [Cloud-to-Cloud Integration for Carbon Black Inventory](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/carbon-black-inventory-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your Carbon Black Inventory app is properly integrated and configured to collect and analyze your Carbon Black Inventory data.
81+
:::
82+
83+
### Create a new collector and install the app
84+
85+
import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md';
86+
87+
<AppCollectionOPtion1/>
88+
89+
### Use an existing collector and install the app
90+
91+
import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
92+
93+
<AppCollectionOPtion2/>
94+
95+
### Use an existing source and install the app
96+
97+
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
98+
99+
<AppCollectionOPtion3/>
100+
101+
## Viewing the Carbon Black Inventory dashboards​​
102+
103+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
104+
105+
<ViewDashboards/>
106+
107+
### Overview
108+
109+
The **Carbon Black Inventory – Overview** dashboard offers a comprehensive snapshot of endpoint assets and their security posture. It highlights key metrics such as total device count, quarantined systems, compliance issues, and devices with outdated scans or disabled protections. The dashboard also provides visibility into inactive or outdated sensors, non-reporting endpoints, and pending sensor updates, along with breakdowns by operating system, vulnerability severity, and geographic location. By consolidating these insights into a unified view, it enables security teams to quickly identify at-risk devices, maintain compliance, and prioritize remediation efforts to improve endpoint hygiene and reduce organizational risk.<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/carbon-black-inventory/Carbon+Black+Inventory+-+Overview.png' alt="Carbon-Black-Inventory-Overview-Dashboard" />
110+
111+
## Create monitors for the Carbon Black Inventory app
112+
113+
import CreateMonitors from '../../reuse/apps/create-monitors.md';
114+
115+
<CreateMonitors/>
116+
117+
### Carbon Black Inventory alerts
118+
119+
| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition |
120+
|:--|:--|:--|:--|
121+
| `Carbon Black Inventory – Devices from Embargoed Locations` | This alert is triggered when one or more endpoints report external IP addresses associated with embargoed or restricted geographies. This helps ensure compliance with corporate and regulatory security requirements. | Critical | Count > 0 |
122+
| `Carbon Black Inventory – Firewall Disabled Devices` | This alert is triggered when an endpoint's host-based firewall protection is disabled, increasing exposure to network-based attacks and lateral movement. | Critical | Count > 0|
123+
| `Carbon Black Inventory – Endpoints Not Reporting` | This alert is triggered when a device has not communicated with Carbon Black for more than 7 days, potentially indicating an unmanaged, offline, or compromised endpoint. | Critical | Count > 0|
124+
| `Carbon Black Inventory – Outdated or Inactive Sensors` | This alert is triggered when endpoints are running outdated sensors or have inactive sensor states, which may reduce visibility and impair policy enforcement. | Critical | Count > 0|
125+
| `Carbon Black Inventory – High Vulnerability Devices` | This alert is triggered when endpoints report high or critical vulnerability scores, highlighting an elevated risk of exploitation and the need for prioritized patching. | Critical | Count > 0|
126+
127+
## Upgrading/Downgrading the Carbon Black Inventory app (Optional)
128+
129+
import AppUpdate from '../../reuse/apps/app-update.md';
130+
131+
<AppUpdate/>
132+
133+
## Uninstalling the Carbon Black Inventory app (Optional)
134+
135+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
136+
137+
<AppUninstall/>

docs/integrations/saas-cloud/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.
9393
<p>Gain insight into user behavior patterns and resources.</p>
9494
</div>
9595
</div>
96+
<div className="box smallbox card">
97+
<div className="container">
98+
<a href="/docs/integrations/saas-cloud/carbon-black-inventory"><img src={useBaseUrl('img/integrations/security-threat-detection/vmcarecb.png')} alt="icon" width="80"/><h4>Carbon Black Inventory</h4></a>
99+
<p>Gain insight into endpoint assets and their security status in your environment.</p>
100+
</div>
101+
</div>
96102
<div className="box smallbox card">
97103
<div className="container">
98104
<a href="/docs/integrations/saas-cloud/cato-networks"><img src={useBaseUrl('/img/send-data/cato-logo.png')} alt="icon" width="80"/><h4>Cato Networks</h4></a>

sidebars.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2554,6 +2554,7 @@ integrations: [
25542554
'integrations/saas-cloud/aws-iam-users',
25552555
'integrations/saas-cloud/bitwarden',
25562556
'integrations/saas-cloud/box',
2557+
'integrations/saas-cloud/carbon-black-inventory',
25572558
'integrations/saas-cloud/cato-networks',
25582559
'integrations/saas-cloud/cisco-amp',
25592560
'integrations/saas-cloud/cisco-meraki-c2c',

0 commit comments

Comments
 (0)