Skip to main content

Carbon Black Cloud

Integrate Carbon Black Cloud with Cloudaware to ingest endpoint alerts, devices, and policies for security reporting and correlation.

info
  • Audience: Cloudaware administrators, SecOps
  • Outcome: The Carbon Black Cloud organization is connected, and endpoint alerts, devices, and policies are available in the CMDB for security reporting and correlation

Capabilities

The integration supports:

  • Discovery of Carbon Black Cloud alerts, devices, and policies in the CMDB
  • Relationships between endpoints, alerts, applications, and related assets
  • Security reporting and dashboards based on Carbon Black Cloud data in Cloudaware

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Org Key, e.g., ABC123XY
  • Base URL (Carbon Black Cloud API endpoint or dashboard URL)
  • API ID and API Secret with read access

Add a Carbon Black Cloud Organization to Cloudaware

To connect your Carbon Black Cloud organization to Cloudaware:

  1. In Cloudaware, go to Admin.
  2. Find Carbon Black Cloud, then click + ADD.
  3. Enter the following values:
    • Name: A display name for this connection
    • Org Key: The Carbon Black Cloud organization key, e.g., ABC123XY
    • Base URL: The Carbon Black Cloud API endpoint or dashboard URL
    • API ID: The API identifier
    • API Secret: The API secret
  4. Click SAVE.
  5. Confirm that the integration status indicator is green.

View Carbon Black Cloud Data in CMDB

To browse discovered Carbon Black Cloud resources:

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select CARBON BLACK CLOUD.
  3. Open an object list, e.g., Carbon Black Cloud Devices, to view records.

Supported Objects

Cloudaware ingests the following Carbon Black Cloud objects:

Carbon Black Cloud ObjectCMDB Object API Name
CBC AlertCA10CBC__CaCbcAlert__c
CBC DeviceCA10CBC__CaCbcDevice__c
CBC OrganizationCA10CBC__CaCbcOrganization__c
CBC PolicyCA10CBC__CaCbcPolicy__c

Troubleshooting

Authentication Fails or Integration Shows Red Status

  • Confirm that the Carbon Black Cloud base URL is correct for the environment.
  • Verify the Org Key, API ID, and API Secret values.
  • Check that the API credentials have read access to alerts, devices, and policies.
  • Re-enter the credentials by editing the integration in Cloudaware.

No Data Appears After a Successful Save

  • Allow the initial discovery cycle to complete.
  • Confirm that the Carbon Black Cloud organization contains alerts, devices, or policies that the API credentials can read.
  • In CMDB Navigator, verify that you are viewing the CARBON BLACK CLOUD section and related resources.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate credentials, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Carbon Black Cloud.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Carbon Black Cloud.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Store secrets in Cloudaware; limit access to admins.
  • Rotate API credentials per policy.