This topic describes how to use the YARA Manager.

  • Log in to your Carbon Black EDR console and browse to https:// <cb_server_url> /connectors/yara , or click YARA Manager on the navigation bar.

YARA Status

The YARA Status page displays YARA Connector status information. The output is taken directly from the Linux service command.

The yara connector status

You can perform the following actions on this page:

  • Get YARA Status — Retrieves the current status of the YARA connector and displays the results in the StdOut and StdErr text boxes.

  • Reset Output — Resets the output.

  • Restart YARA — Restarts the YARA connector.

  • Reset DB — Resets the threat reports database to its empty state. This is typically used after adding YARA rules.

YARA Rules Manager

On the YARA Rules Manager page, you can upload, delete, and download YARA rule files.

The yara rules manager

To upload a new YARA rule, click the Choose File button, select the appropriate . yar file, and click the Upload Rule button.

The YARA Manager supports the upload of multiple YARA rules. You can upload a zip file that contains multiple YARA rules. The YARA Manager extracts the zip file and puts all the rules in the path that the YARA connector configuration file specifies.

To delete all YARA rules click the Purge all Rules button. Alternatively, you can individually download or delete YARA rules.

YARA Configuration

The YARA Configuration page displays the current configuration of the YARA connector.

This information is gathered from the YARA connector’s configuration file. You cannot edit this page; you can only make changes through the connector.conf file.

The yara configuration

YARA Log

The YARA Log page displays the contents of the /var/log/cb/integrations/yara-manager/debug.log file.

The YARA log