Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Inconsistent results between Alert and Investigate tab when using watchlist_name

Carbon Black Cloud: Inconsistent results between Alert and Investigate tab when using watchlist_name

Environment

  • Carbon Black Cloud: All Versions

Symptoms

  • Investigate tab shows results for a search with watchlist_name
  • Alerts tab shows 0 results for the same search

Cause

Trailing space in watchlist_name search parameter not being handled consistently (DSER-32937)

Resolution

  1. Review your search string for any trailing spaces and remove them
  2. If the issue is not resolved with this change, please log a new support ticket with search examples that show the issue.

Additional Notes

  • Example watchlist name is actually "test"
  • watchlist_name:"test" is the correct search to use
  • watchlist_name:"test " will return hits for "test" watchlist in Investigate tab
  • watchlist_name"test "  will NOT return results for "test" watchlist in Alerts tab.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-22-2022
Views:
415
Contributors