Security Operations Carbon Black Integration - Get Running Processes Flow
The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.
Role required: sn_si.analyst
Image omitted: carbon-black-get-running-proccess-1.png
Flow Design for Security Operations Carbon Black Integration - Get Running Processes 1 \[Omitted image "carbon-black-get-running-proccess-2.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 2 \[Omitted image "carbon-black-get-running-proccess-3.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 3 \[Omitted image "carbon-black-get-running-proccess-4.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 4 \[Omitted image "carbon-black-get-running-proccess-5.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 5
Flow Design for Security Operations Carbon Black Integration - Get Running Processes 1 \[Omitted image "carbon-black-get-running-proccess-2.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 2 \[Omitted image "carbon-black-get-running-proccess-3.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 3 \[Omitted image "carbon-black-get-running-proccess-4.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 4 \[Omitted image "carbon-black-get-running-proccess-5.png"\] Alt text: Flow Design for Security Operations Carbon Black Integration - Get Running Processes 5
Actions specific to this flow are described here. For more information on other actions, see Common Security Operations integration flows and orchestration activities.
- Collect Carbon Black Configurations Flow Action
The Collect Carbon Black Configurations flow action gathers configuration information to use in the flow. - Check MID Server Status
Determines whether the MID Server identified in the MID Server Host field of the integration's configuration is up and running. If the field is set to Any, the flow action verifies that any MID Server is up and running. - Get Sensor ID Flow Action
The Get Sensor ID flow action gathers sensor identifiers to use in the flow. - Create Session Flow Action
The Create Session flow action establishes a Carbon Black session to use in the flow. - Check Session Status Flow Action
Determines the status of a Carbon Black session within the flow. - Create Command Process Flow Action
The Create Command Process flow action create a Carbon Black command process to use in the flow . - Check Command Status and Get Process Flow Action
Checks the Carbon Black command status and retrieves processes to use in the flow. - Map Processes Data Flow Action
The Map Processes Data flow action maps Carbon Black process data within the flow. - Capability Execution Tracking - Complete Flow Action
The Capability Execution Tracking - Complete flow action updates the audit record when the flow is complete. - Close Session Flow Action
Closes a Carbon Black session within the flow.
Parent Topic:Security Operations Integration- Get Running Processes capability