IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.

CBC: Querying the "fileless_scriptload_cmdline" field can return additional hits that don't APPEAR to match the value.

Environment

  • CBC Console: 1.3 and earlier
  • CBC Windows Sensors: All versions
  • Microsoft Windows: All versions

Symptoms

Querying on the fileless_scriptload_cmdline may return additional process hits where the CMD field (in the process analysis pages) does not render the string searched for.

Cause

This is internal issue LC-1971. In reality, the string DOES occur, and therefore the query is ACCURATE.
What's occurring is the CMD field is so large, it cannot fit into the UI.
The queried string CAN be seen by turning on Chrome Devtools and rendering the process analysis page
where the string can be found in a  "results" field/

Resolution

Feature Request "FR-002859" has been created which will likely create a new field to render the CMD results properly.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-05-2022
Views:
304
Contributors