Environment
- Carbon Black Cloud: All versions
Question
When forwarding events, what field shows the observed / threat alert categories?
Answer
As of APIv6, this information is stored in the 'category' field, the description will vary by where it is viewed
UI | Threat | Observed |
API | THREAT | MONITORED |
Date Forwarder | WARNING | NOTICE |
Related Content