Carbon Black Cloud: What field can be used to determine the observed / threat alert categories?
book
Article ID: 290312
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
When forwarding events, what field shows the observed / threat alert categories?
Environment
- Carbon Black Cloud: All versions
Resolution
As of APIv6, this information is stored in the 'category' field, the description will vary by where it is viewed
UI | Threat | Observed |
API | THREAT | MONITORED |
Date Forwarder | WARNING | NOTICE |
Feedback
thumb_up
Yes
thumb_down
No