IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to create Advanced Process Search Queries

EDR: How to create Advanced Process Search Queries

Environment

  •  EDR: All supported versions

Objective

  • How to create Advanced Process Search Queries

Resolution


Additional Notes

  • The CB Response console provides a check box interface to choose criteria for searches of processes, binaries, alerts, and threat reports. However this chapter describes how to construct more complex queries.
  • The guide provides more details on terms, operators and fields that can be used to construct queries which can be run across process search, binary search, alerts and threat reports.

Labels (1)
Tags (2)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
3066
Contributors