IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Audit and Remediation: How to Free-Form Query Endpoints

Audit and Remediation: How to Free-Form Query Endpoints

Environment

  • Carbon Black Cloud Console: 0.38 Release and higher
    • Audit and Remediation
  • Carbon Black Cloud Linux Sensor: 2.3.x.x and Higher
  • Carbon Black Cloud macOS Sensor: 3.3.x.x and Higher
  • Carbon Black Cloud Windows Sensor: 3.3.x.x and Higher

Objective

Run a custom query using Audit and Remediation

Resolution

  1. Go to Live Query > New Query
  2. Click SQL Query tab
  3. Enter name of query for reference (required)
  4. Enter desired query in SQL box
  5. Select specific Policy(ies) or Endpoint(s) as desired
  6. Click Run

    Additional Notes

    Results can take some time to be returned. This is expected behavior. If you need assistance with SQL syntax, or table schema, please refer to the documentation links for each in the "SQL Query" tab.
    • A summary email can be sent, indicating the results are available in the console by selecting the "Email me when complete" option when creating the query
    • On submitting a query, either a green( success) status message, or a red( failure) message will be displayed
      • For failure messages, please note the message, adjust the query, and try again
      • For success messages, please continue to monitor the Live Query console for results to be returned, or look for an email to be sent when the query completes, then come back to the console to view results

    Related Content


    Was this article helpful? Yes No
    100% helpful (1/1)
    Article Information
    Author:
    Creation Date:
    ‎09-11-2018
    Views:
    806
    Contributors