Search Discrepancies Between Watchlist Hits and Query Hits
search cancel

Search Discrepancies Between Watchlist Hits and Query Hits

book

Article ID: 384569

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR

Issue/Introduction

Why do watchlist hits and reviewing the query results for the same time period return different results?

Environment

  • Carbon Black Cloud Console: All Supported Versions

Cause

Watchlist hits are 1 hour rolling windows vs a query which is not doing a point in time analysis of the data

Resolution

  • A normal investigate search does not replicate the 1 hour rolling window that is used in watchlist query detections.
  • The closest thing that can be done is determining when the hit happened and limiting the search from that time minus 1 hour to that time, but even that will not be perfect because the time windows on investigate are fluid.

Additional Information

For long running processes, performing queries that do logical AND on multiple events or that negate an event are subject to a time window.