Skip to main content

Carbon Black

With this integration, you can collect Logs from Carbon Black and forward them to Logz.io.

Set Carbon Black Event Forwarder​

Follow Carbon Black instructions for forwarding events to S3 bucket

Create new stack​

To deploy this project, click the button that matches the region you wish to deploy your stack to:

RegionDeployment
us-east-1Deploy to AWS
us-east-2Deploy to AWS
us-west-1Deploy to AWS
us-west-2Deploy to AWS
eu-central-1Deploy to AWS
eu-north-1Deploy to AWS
eu-west-1Deploy to AWS
eu-west-2Deploy to AWS
eu-west-3Deploy to AWS
sa-east-1Deploy to AWS
ap-northeast-1Deploy to AWS
ap-northeast-2Deploy to AWS
ap-northeast-3Deploy to AWS
ap-south-1Deploy to AWS
ap-southeast-1Deploy to AWS
ap-southeast-2Deploy to AWS
ca-central-1Deploy to AWS

Specify stack details​

Specify the stack details as per the table below, check the checkboxes and select Create stack.

ParameterDescriptionRequired/Default
logzioListenerThe Logz.io listener URL for your region. (For more details, see the regions pageRequired
logzioTokenYour Logz.io log shipping token.Required
logLevelLog level for the Lambda function. Can be one of: debug, info, warn, error, fatal, panic.Default: info
logTypeThe log type you'll use with this Lambda. This is shown in your logs under the type field in OpenSearch Dashboards. Logz.io applies parsing based on the log type.Default: s3_hook
pathsRegexesComma-seperated list of regexes that match the paths you'd like to pull logs from.-
pathToFieldsFields from the path to your logs directory that you want to add to the logs. For example, org-id/aws-type/account-id will add each of the fields ord-id, aws-type and account-id to the logs that are fetched from the directory that this path refers to.-

Add trigger​

After deploying the stack, wait a few minutes for it to complete. Once your Lambda function is ready, you'll need to manually add a trigger due to CloudFormation limitations:

  1. Navigate to the function's page and click on Add trigger.

  2. Choose S3 as a trigger, and fill in:

    • Bucket: Your bucket name.
    • Event type: Select All object create events.
    • Prefix and Suffix: Leave these fields empty.

    Confirm the checkbox, and click Add.

Send logs​

Your function is now configured. When you upload new files to your bucket, the function will be triggered, and the logs will be sent to your Logz.io account.

Parsing​

The S3 Hook will automatically parse logs if the object's path contains the phrase cloudtrail (case insensitive).

Check your logs​

Allow some time for data ingestion, then check your OpenSearch Dashboards.

Encounter an issue? See our log shipping troubleshooting guide.