Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

VMware Carbon Black Cloud Sentinel Data connector not ingesting alerts- Sentinel

Open sandeep5234 opened this issue 8 months ago • 14 comments

We have updated the VMware carbon black data connector to new version. There are 2 functions in it, The audit event function is working ok. But AlertsAPITimer function is not ingesting data. We have noticed that ORG KEY ID is a new field required as well because notification_cl is deprecated. We have added the ORK KEY ID into Environmental variables. But this didn't fix the issue.

We can see there are no errors as well. But there is no data as well for alerts, We have triggered few test alerts from Carbon black console, but still no data. This is all the output we see image

sandeep5234 avatar Jun 20 '24 00:06 sandeep5234