OTHER SIEM INTEGRATION CASE STUDIES
Pulse Secure integration (Add-on) with SplunkIntegration with LogRhythm
Secure Access Platform integration(Add-on and App ) with Splunk
CASB Platform integration (Add-on and App ) with Splunk
DNS Platform integration (App ) with Splunk
Business Risk Intelligence Platform integration ( Add-on) with Splunk
Infrastructure Monitoring Platform integration ( Add-on) with Splunk
Categories
Customer
Customer is a leading SIEM solution provider.
They provide a platform for companies to aggregate and act upon Threat Intelligence.
Requirement
Customer requested for the integration of their product with Carbon Black
Technology Solution
Sacumen developed the Connector app that enhances the threat detection capabilities of SIEM platform by collecting and analysing log data from the Carbon Black applications and provides orchestration actions to streamline incident response activities.
CB Response, CB Protection, CB Defense sends the syslog to the SIEM’s syslog server. Connector App processed the incoming syslog, parses it, maps to events fields and feed into the SIEM Platform
SIEM initiates call to CB Response to isolate an endpoint instantly – through a user-executed action or an automated rule. Connector makes REST API call to CB Response to isolate an end point
There are no reviews yet.