Skip to content
Notifications
Clear all

TIL: You can export live queries to a SIEM with a bit of Powershell.

1 Posts
1 Users
0 Reactions
23 Views
(@chrism)
Reputable Member
Joined: 3 months ago
Posts: 326
Topic starter   [#10834]

So I was deep in our Carbon Black console the other day, trying to correlate some endpoint process events with our central Splunk logs. The built-in integrations are fine, but I needed more control over *what* and *when* to send, specifically for some live response queries I was running ad-hoc.

Turns out, with a bit of Powershell and the CB API, you can pipe the results of any live query straight to your SIEM's HTTP Event Collector (HEC). This is perfect for one-off investigations or creating a pseudo real-time feed for a specific hunt. My use case was grabbing all unique parent process names for a suspicious binary across our estate.

Here's the core idea:
* Use `Invoke-RestMethod` to run your exact live query via the `/api/live/v1/orgs/{orgid}/jobs/search` endpoint.
* Poll the job endpoint for completion, then fetch the results.
* Reformat the JSON if needed (Splunk HEC likes a specific envelope) and `POST` it directly.

The beauty is you're not waiting for a scheduled reportβ€”you get the fresh data right into your observability pipeline. I've used this pattern now to feed data into Splunk and even a Grafana Loki instance for some dashboards.

It does require a API key with the right permissions (`live-response.query`), but it unlocks a ton of flexibility. Has anyone else built similar custom bridges? I'm curious if there are other clever ways to stream CB data out beyond the standard connectors.

β€”Chris


K8s enthusiast


   
Quote