Does Panther support natively importing alerts produced by CarbonBlack within Panther as log events?
QUESTION
Does Panther support natively importing alerts produced by CarbonBlack within Panther as log events?
ANSWER
Panther does not currently support importing alerts produced by CarbonBlack within Panther as log events. If you are interested in this feature, please contact Panther Support to put in a request.
As a workaround, you can ingest these logs by creating a custom schema and using a data transport method for the onboarding of the logs, such as an S3 bucket.