CB ThreatHunter: How to filter out data with unknown event type counts
book
Article ID: 290307
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Filter out data that contains an (unknown) field for the event type count e.g. regmods, filemods, etc.
Environment
- CB ThreatHunter Console: All Versions
Resolution
On the investigate page within the ThreatHunter console use the following search syntax
Feedback
thumb_up
Yes
thumb_down
No