IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Does a Wildcard Query on a Search Field Return Null Values?

Carbon Black Cloud: Does a Wildcard Query on a Search Field Return Null Values?

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud APIs

Question

  • Are wildcard queries against a search field expected to return results containing no value?
  • Example: Would the following query return unsigned processes?  
    process_publisher:*

Answer

  • No, query results will not include results where the field searched contains a null value.
  • In the example provided, only signed processes would be returned because unsigned processes contain no value for the process_publisher field. 

Additional Notes

Advanced search criteria and operators can be leveraged to obtain the desired results.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-15-2023
Views:
323
Contributors