CB Response: Process queries with binary joins incorrectly handle group and OS negation
book
Article ID: 289660
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
When performing a process search with binary fields, and also group and OS negation, the results will be incorrect.
Environment
- CB Response server: 6.2.2 and above
Resolution
The bug will be fixed in a future release.
The workaround is to add "group:*" or "os_type:*" in the query.
Feedback
thumb_up
Yes
thumb_down
No