Back to Blogs

Announcing Carbon Black Cloud App for Splunk SIEM v2.2.0

Posted on May 23, 2024

We’re pleased to announce version 2.2.0 of the Carbon Black Cloud App for Splunk SIEM.

New Features

  • v2.2.0
    • Inputs and API Configurations have Test Config buttons to help test permissions and configurations prior to implementation.
  • v2.1.0
    • Asset Inventory Input, including USB Devices

Improvements & Fixes

  • v2.2.0
    • Live Query Input can ingest more than 10,000 events per run history found.
    • Fixed an issue where the IA (Input AddOn) did not provide a required python file and resulted in an error.
    • Removed a hard-coded IP address in the Asset Details dashboard
  • v2.1.0
    • Index drop downs will support more than 30 indexes.


If you’re upgrading from v1.x.x of the App, there are breaking changes to be aware of and actions you need to take.

Read Before you Upgrade to Splunk SIEM App v2.x.x


Have questions or feedback?