Why do the Threat Reports "search for threat" links show no hits?
book
Article ID: 372595
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
When trying to view the Threat Report hits using the "search for threat" buttons there are no results
Environment
Carbon Black Cloud: All Supported Versions
Cause
- There may be no legitimate hits in the environment as these are supposed to be capturing potentially malicious behavior
- Hits that these watchlists find may also be under the Processes tab while the link may go to the Observations tab
Resolution
- Go to the Processes tab when looking for hits with these queries
- For testing the queries can be triggered on purpose to test and confirm that data is being sent to the cloud correctly
Feedback
thumb_up
Yes
thumb_down
No