Carbon Black EDR Event Forwarder
About 9,840 records/day from ten workstations and two automation servers, with legacy ingress JSON and selected Elastic normalization.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-carbon-black-edr-event-forwarder/generator.yml \
--id carbonblack \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| ingress.event.procstart | Process starts | 6.1% | process |
| ingress.event.procend | Process exits | 6.1% | process |
| ingress.event.regmod | Temporary registry value written or deleted | 3.0% | registry |
| ingress.event.filemod | Temporary file written or deleted | 10.2% | file |
| ingress.event.netconn | Outbound application connection | 74.6% | network |
Realism Features
- Stable process identity and GUIDs encoding sensor, PID and creation time
- Temporary registry values and files are removed before process exit
- Selected ingress types; executable hashes and parent references are synthetic
Sample Output
{
"@timestamp": "2026-09-21T00:00:33.394736+00:00",
"carbonblack": {
"edr": {
"command_line": "\"c:\\program files\\Fabrikam\\update.exe\"",
"computer_name": "SRV-OPS-01",
"event_type": "proc",
"expect_followon_w_md5": false,
"filtering_known_dlls": false,
"link_parent": "https://cb-01.example.test/#analyze/0000001f-0000-05dc-01dd-494b758411e0/1",
"link_process": "https://cb-01.example.test/#analyze/0000001f-0000-07d4-01dd-495c390ce1e0/0",
"link_sensor": "https://cb-01.example.test/#/host/31",
"md5": "90A22F0022EB9B544F2731AA76C9C3C3",
"parent_create_time": 1789941633,
"parent_guid": "0000001f-0000-05dc-01dd-494b758411e0",
"parent_md5": "CC528C115378F7E5EB404837962C2206",
"parent_path": "c:\\windows\\explorer.exe",
"parent_pid": 1500,
"parent_process_guid": "0000001f-0000-05dc-01dd-494b758411e0",
"path": "c:\\program files\\Fabrikam\\update.exe",
"pid": 2004,
"process_guid": "0000001f-0000-07d4-01dd-495c390ce1e0",
"process_path": "c:\\program files\\Fabrikam\\update.exe",
"sensor_id": 31,
"sha256": "357DA3610A6743839006711F24AB657BAEBF808A58EFE5761F742A4F9A75F2AD",
"timestamp": 1789948833.394736,
"username": "svc-monitor1@example.test"
}
},
"ecs": {
"version": "8.11.0"
},
"event": {
"action": "ingress.event.procstart",
"dataset": "carbonblack_edr.log",
"kind": "event",
"original": "{\"cb_server\": \"cb-01.example.test\", \"command_line\": \"\\\"c:\\\\program files\\\\Fabrikam\\\\update.exe\\\"\", \"computer_name\": \"SRV-OPS-01\", \"event_type\": \"proc\", \"expect_followon_w_md5\": false, \"filtering_known_dlls\": false, \"link_parent\": \"https://cb-01.example.test/#analyze/0000001f-0000-05dc-01dd-494b758411e0/1\", \"link_process\": \"https://cb-01.example.test/#analyze/0000001f-0000-07d4-01dd-495c390ce1e0/0\", \"link_sensor\": \"https://cb-01.example.test/#/host/31\", \"md5\": \"90A22F0022EB9B544F2731AA76C9C3C3\", \"parent_create_time\": 1789941633.394736, \"parent_guid\": \"0000001f-0000-05dc-01dd-494b758411e0\", \"parent_md5\": \"CC528C115378F7E5EB404837962C2206\", \"parent_path\": \"c:\\\\windows\\\\explorer.exe\", \"parent_pid\": 1500, \"parent_process_guid\": \"0000001f-0000-05dc-01dd-494b758411e0\", \"path\": \"c:\\\\program files\\\\Fabrikam\\\\update.exe\", \"pid\": 2004, \"process_guid\": \"0000001f-0000-07d4-01dd-495c390ce1e0\", \"process_path\": \"c:\\\\program files\\\\Fabrikam\\\\update.exe\", \"sensor_id\": 31, \"sha256\": \"357DA3610A6743839006711F24AB657BAEBF808A58EFE5761F742A4F9A75F2AD\", \"timestamp\": 1789948833.394736, \"type\": \"ingress.event.procstart\", \"username\": \"svc-monitor1@example.test\"}"
},
"observer": {
"name": "cb-01.example.test",
"product": "Carbon Black EDR",
"type": "edr",
"vendor": "VMWare"
},
"tags": [
"carbonblack_edr-log",
"forwarded",
"preserve_original_event"
]
}Parameters
| Parameter | Default | Description |
|---|---|---|
| cb_server | cb-01.example.test | EDR server name |
| link_base | https://cb-01.example.test/ | Console base URL for process and sensor links |
| anomaly_mode | true | Include recurring correlated process activity |
| anomaly_interval_hours | 24 | Episode interval in hours, from 2 to 8760 |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.