Carbon Black Cloud: Alert searches are not reporting watchlist-generated alerts when the field_name is not specified.
book
Article ID: 288252
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Go to the Alerts page
search for "device_name:Mylaptop1" - this works.. both watchlist and CB Analytics alerts are reported.
now search for just "Mylaptop1" - this fails and ONLY returns CB Analytics alerts
device_name: Mylaptop1 <-- this works
Mylaptop1 <-- this will not return watchlist-generated alerts for the machine Mylaptop1
The problem occurs with other fields as well and is not limited to the "device_name" field. For instance, the "watchlist_name" field also exhibits the same symptoms
Environment
CBC Console: .75.0
CBC Sensors: All versions
Cause
Now under investigation. This article will flip to public once further confirmed by Engineering.