IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB ThreatHunter: How to search based on event_timestamp

CB ThreatHunter: How to search based on event_timestamp

Environment

  • CB ThreatHunter Web Console: All Versions
  • CB PSC Sensor: 3.4.x.x and higher
  • Microsoft Windows: All Supported Versions

Objective

Filter events on the Process Analysis page using the event_timestamp search field

Resolution

  1. Navigate to the Investigate page
  2. Select the desired process name hyperlink or select the Process Analysis icon
  3. Within the Process Analysis page scroll down to the search bar
  4. Enter the event_timestamp search field in the search bar utilizing the following syntax
    • event_timestamp:[YYYY-MM-DDTHH:MM:SS TO YYYY-MM-DDTHH:MM:SS]

Additional Notes

  • Specifying a timezone for the event_timestamp search field is currently not possible
  • Times that are entered in the event_timestamp search field will need to account for the UTC timezone. For example:
    • A user based in the EDT timezone filtering for events that happened at 6:00 a.m. will need to enter 10:00 a.m. for the time range in the above event_timestamp syntax example

Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-10-2020
Views:
604
Contributors