Carbon Black Cloud
Integrate Carbon Black Cloud with Cloudaware to ingest endpoint alerts, devices, and policies for security reporting and correlation.
info
- Audience: Cloudaware administrators, SecOps
- Outcome: The Carbon Black Cloud organization is connected, and endpoint alerts, devices, and policies are available in the CMDB for security reporting and correlation
Capabilities
The integration supports:
- Discovery of Carbon Black Cloud alerts, devices, and policies in the CMDB
- Relationships between endpoints, alerts, applications, and related assets
- Security reporting and dashboards based on Carbon Black Cloud data in Cloudaware
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Org Key, e.g.,
ABC123XY - Base URL (Carbon Black Cloud API endpoint or dashboard URL)
- API ID and API Secret with read access
Add a Carbon Black Cloud Organization to Cloudaware
To connect your Carbon Black Cloud organization to Cloudaware:
- In Cloudaware, go to Admin.
- Find Carbon Black Cloud, then click + ADD.
- Enter the following values:
- Name: A display name for this connection
- Org Key: The Carbon Black Cloud organization key, e.g.,
ABC123XY - Base URL: The Carbon Black Cloud API endpoint or dashboard URL
- API ID: The API identifier
- API Secret: The API secret
- Click SAVE.
- Confirm that the integration status indicator is green.
View Carbon Black Cloud Data in CMDB
To browse discovered Carbon Black Cloud resources:
- In Cloudaware, open CMDB Navigator.
- In the left pane, select CARBON BLACK CLOUD.
- Open an object list, e.g., Carbon Black Cloud Devices, to view records.
Supported Objects
Cloudaware ingests the following Carbon Black Cloud objects:
| Carbon Black Cloud Object | CMDB Object API Name |
|---|---|
| CBC Alert | CA10CBC__CaCbcAlert__c |
| CBC Device | CA10CBC__CaCbcDevice__c |
| CBC Organization | CA10CBC__CaCbcOrganization__c |
| CBC Policy | CA10CBC__CaCbcPolicy__c |
Troubleshooting
Authentication Fails or Integration Shows Red Status
- Confirm that the Carbon Black Cloud base URL is correct for the environment.
- Verify the Org Key, API ID, and API Secret values.
- Check that the API credentials have read access to alerts, devices, and policies.
- Re-enter the credentials by editing the integration in Cloudaware.
No Data Appears After a Successful Save
- Allow the initial discovery cycle to complete.
- Confirm that the Carbon Black Cloud organization contains alerts, devices, or policies that the API credentials can read.
- In CMDB Navigator, verify that you are viewing the CARBON BLACK CLOUD section and related resources.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Carbon Black Cloud.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Carbon Black Cloud.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Store secrets in Cloudaware; limit access to admins.
- Rotate API credentials per policy.