Blog Viewer

CB Response: How to prevent searches on empty fields in a query

By CB_Support posted Sep 10, 2020 02:20 AM

  

Environment

  • CB Response Server: 6.0 and Above

Objective

  • Query on a specific field only if there is a value in the field 

Resolution

  • Use the wildcard operator (*) with the field name to return results which only contain a value in that field.
    • field_name:*

       

Additional Notes

  • This can be used to improv query performance even when querying for specific values in a field.
    • domain:* AND -domain:carbonblack.com

       


#EDR
0 comments
0 views

Permalink