↳ GitHub sourceConnector

VMware Carbon Black Cloud via AWS S3

An inconsistency was detected in the sources: variants or an invalid file. Check the files and commit shown below.

Description

The [VMware Carbon Black Cloud](https://www.broadcom.com/products/carbon-black/threat-prevention/carbon-black-cloud) via AWS S3 data connector provides the capability to ingest watchlist, alerts, auth and endpoints events via AWS S3 and stream them to ASIM normalized tables. The connector provides ability to get events which helps to examine potential security risks, analyze your team's use of collaboration, diagnose configuration problems and more.
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

write permission.
Workspace
Workspace
Environment
You must have the following AWS resources defined and configured: S3, Simple Queue Service (SQS), IAM roles and permissions policies
Environment
You must have the a Carbon black account and required permissions to create a Data Forwarded to AWS S3 buckets. 
For more details visit [Carbon Black Data Forwarder Docs](https://docs.vmware.com/en/VMware-Carbon-Black-Cloud/services/carbon-black-cloud-user-guide/GUID-E8D33F72-BABB-4157-A908-D8BBDB5AF349.html)

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Template 1: OpenID connect authentication deployment
Template 2: AWS Carbon Black resources deployment
Workspace ID
Add new controller
Add new collector
Account details
Role ARN
Queue URL
Data type
Alerts
Auth Events
Endpoint Events
Watchlist

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
carbonBlackAWSS3
Additional source files 1Solutions/VMware Carbon Black Cloud/Data Connectors/CarbonBlackViaAWSS3_ConnectorDefinition.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.