In this article, you'll learn how to integrate Carbon Black with Real-Time Coaching. Once the integration is complete, data from Carbon Black will be available in the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Carbon Black
Before you can set up this integration in Real-Time Coaching, you'll need to create a custom access level and an API key. For more information, see the subsections below.
Create a Custom Access Level
To create a custom access level in Carbon Black, follow the steps below:
- Log in to your Carbon Black Cloud console.
- Navigate to Settings > API Access > Access Levels.
- Select Add Access Level.
-
In the Access Level section, enter a unique name and a description for your custom access level.
Important:You'll need a level with a unique name to create an API key. -
In the permissions table, locate the API Service Category and select the following Access Level permissions:
- For the category Alerts > General Information > org.alerts, enable the READ check box.
- For the category Alerts > Notes > org.alerts.notes, enable the READ check box.
Create an API Key
After you’ve created your custom access level, you can create your Carbon Black API key.
To create an API key, follow the steps below:
- Log in to your Carbon Black Cloud console.
- Navigate to Settings > API Access > API Keys.
- Select Add API Key. An Add API Key window will display.
-
To configure the Add API Key window, see the screenshot and list below:
-
Name: Enter a unique name for the API Key.
Note:Choose a name that clearly distinguishes the API key from your organization’s other API keys. - Access Level Type: Select Custom.
- Custom access level: Select the access level you created in the Creating a Custom Access Level article section.
-
- Select Save. After you select Save, your API Key Credentials will display, including your API Key and API ID.
- Copy and save the API Key and API ID somewhere you can easily access them. You'll need these to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
To register Carbon Black with Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Carbon Black vendor tile and select Configure to open the vendor setup page.
- Enter the API ID and API Key that you created in Carbon Black.
- Enter the API Domain that is displayed in the URL of your Carbon Black Cloud console. For example, if your console URL is “https://dashboard.confer.net/”, your API domain would be “dashboard.confer.net”.
- Enter the Org Key that is displayed in the Settings > API Access window of your Carbon Black Cloud console.
- Select Authorize.
Map Your Users
After you’ve finished integrating Carbon Black, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Carbon Black detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Carbon Black integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Carbon Black vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.


