VMware Carbon Black Cloud Enterprise EDR

Modified on Wed, 06 Sep 2023 at 02:58 AM

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai Help Center and we'll get it updated.


This guide describes the steps required to configure VMWare Carbon Black Cloud Enterprise EDR to send logs to the Samurai XDR.  


 

mceclip0.png VMWare Carbon Black Cloud Enterprise EDR logs and data are collected via REST API and Streaming API.

 

To complete this Integration you will need to:

1) Within the VMware Carbon Black Cloud web interface

  • Determine environment 
  • Determine Org key for API Access
  • API Access


2) From the Samurai XDR application:

  • Complete the Carbon Black Cloud Enterprise EDR Integration

 

VMware Carbon Black Cloud

Determine Environment

The URL for API access appears in the address bar in a browser as follows:

https://defense-"Envionment-hostname".conferdeploy.net


mceclip0.png Take note of this URL as it will be required when completing the Integration within the Samurai XDR application.

 

Determine Org Key for API Access

To determine your Org Key for API Access:

  1. Login to your Carbon Black Cloud instance
  2. Select Settings > API Access
  3. The ORG KEY  is shown on the screen.


mceclip0.png Take note of this Org Key as it will be required when completing the Integration within the Samurai XDR application.

 

API Access

Use these steps to configure a custom API access level:

  1. Log in to your Carbon Black Cloud Instance with an account that has the Super Admin role.
  2. Click Settings > API Access
  3. Go to the Access Level tab
  4. Click Add Access Level
    1. In the Name field, enter Samurai-Access
    2. Enter a description
    3. Select the following permissions 
    4. org.alerts Read
    5. device Read
    6. org.search.events Read
    7. device.quarantine Execute (Optional, for Remote Isolation)
  5. Click Save

Use these steps to enable API configuration to allow Samurai XDR to gather telemetry:

  1.  Click Settings > API Access
  2.  Click + Add API Key
  3.  Add a new API key with the following information:
    1. In the Name field, enter Samurai-XDR
    2.  From the Access Level type list, select Custom
    3. From Custom Access Level list, select Samurai-Access
    4. Click Save
  4. The API credentials are displayed
  5.  Use the copy button to copy the Samurai-XDR API ID and API Secret Key. Paste the information to a file clearly indicating name, API ID, and API secret key.


mceclip0.png You will need the API ID and API Secret key when completing the integration within the Samurai XDR application.

 

Configure the Samurai XDR Application

Complete the VMware Carbon Black Cloud Enterprise EDR Integration


  1. Login to your Samurai XDR tenant
  2. Select Telemetry > Integrations
  3. Select Create
  4. Locate and click Carbon Black Enterprise EDR
  5. Click Next (we leverage a Samurai XDR Cloud Collector)
  6. Enter a Name of Integration
  7. Enter a Description (Optional)
  8. Enter your Devicename
  9. Enter your Environment-hostname
  10. Enter your Organization Key
  11. Enter your API ID
  12. Enter your API Secret
  13. Click Finish