EDR: Cannot Add Watchlist with '%' or '=' in Watchlist Text

EDR: Cannot Add Watchlist with '%' or '=' in Watchlist Text

Environment

  • EDR Server: 7.5.x

Symptoms

  • 400 HTTP Error received when attempting to add a watchlist with either '=' or '%' symbols in the watchlist.  This primarily occurs on the Watchlists UI page.
  • Error observed in UI:
    • User-added image

Cause

  • Defect causes error during URL encoding, which can cause the error below which can be observed when looking at a .har file of the upload/save attempt.
"The query_string contains a bare '%' which should be '%25'"

 

Resolution

  • This is a current defect and will be addressed in a future version of EDR.
  • To workaround the issue:
    1. Go to the Process Search page in the EDR UI.
    2. Search for the Query that's needed to become a watchlist.
    3. Click the 'Create Watchlist' button on the right side of the UI.
    4. Fill in the appropriate details and save.
  • Note: If any edits need to be done to the watchlist after addition, removal of the watchlist and adding it back in per the steps above will be required until the defect is fixed in an upcoming EDR release.

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-06-2021
Views:
172
Contributors