IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Enterprise EDR: How to add queries to watchlists from the Investigate page

Enterprise EDR: How to add queries to watchlists from the Investigate page

Environment

Enterprise EDR Console: All Versions

Objective

Integrate unique threat intelligence by adding custom queries to watchlist reports

Resolution

  1. Navigate to the Investigate page
  2. Execute the desired query in the search bar
  3. Verify the results are what is expected
  4. Select Add search to Threat Report under the search magnifying glass
  5. Select an existing custom Watchlist or create a new custom Watchlist
  6. Add the search query to an existing Threat Report or create a new Threat Report
  7. Select Save

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
3312
Contributors