How to Build a Custom Watchlist From the Investigate Page
search cancel

How to Build a Custom Watchlist From the Investigate Page

book

Article ID: 290537

calendar_today

Updated On: 04-09-2025

Products

Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Create a custom watchlist from the Investigate page

Environment

  • Enterprise EDR Console: All Versions

Resolution

  1. Navigate to the Investigate page
  2. Execute a desired search query
  3. Select Add search to watchlist report under the search magnifying glass
  4. Under the Select Watchlist heading in the modal, select Create new watchlist
  5. Enter a name for the watchlist
  6. Enter a description for the watchlist if desired
  7. Enable Alert on Hit if the watchlist is desired to alert users when IOCs match incoming data
    • Selecting Evaluate on all existing data will perform a one time query of all past data available in the console
  8. Enter a name for the Select Report that will contain the search query executed previously in step 2
  9. Enter a description for the report if desired
  10. Set a desired severity
  11. Enter any tags to be applied to the report
  12. Select Save

Additional Information

Additional product documentation for using watchlists can be found here