Carbon Black Cloud Host-based Firewall events display on the Investigate page. All firewall events are Type netconn
.
Procedure
- In the left navigation pane, click Investigate.
- Click the Observations tab.
- Build a search query using the following search string:
event_type:NETWORK AND firewall
- View events that were initiated by a firewall rule; for example:
Note: To reduce noise on the Investigate and Alert Triage pages, Carbon Black can limit the number of events associated with an alert that a specific Host-based Firewall rule generates. This limit will never be less than 100 events.