EDR: Can watchlists and feeds be assigned to specific endpoints or groups?
book
Article ID: 289580
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Can a watchlist or feed only alert on specific sensors / groups?
Resolution
- Watchlists can use the group or hostname fields to filter on a specific group / computer respectively
- Feeds cannot be run against a specific group, but a watchlist can be created off the feed and filter the group
- On the desired feed, click "Process Matches" to go to the investigate page.
- In the investigate page, add the 'group' or 'endpoint' field
ex. (alliance_score_srstrust:*) and group:"<group_name>" - Select "Create Watchlist" and save the watchlist
- If not already enabled, go back to the threat feed and enable it.
- Disable any notifications in the feed itself and enable notifications on the watchlist
Feedback
thumb_up
Yes
thumb_down
No