Search Discrepancies Between Watchlist Hits and Query Hits
book
Article ID: 384569
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR
Issue/Introduction
Why do watchlist hits and reviewing the query results for the same time period return different results?
Environment
Carbon Black Cloud Console: All Supported Versions
Cause
Watchlist hits are 1 hour rolling windows vs a query which is not doing a point in time analysis of the data
Resolution
A normal investigate search does not replicate the 1 hour rolling window that is used in watchlist query detections.
The closest thing that can be done is determining when the hit happened and limiting the search from that time minus 1 hour to that time, but even that will not be perfect because the time windows on investigate are fluid.
Additional Information
For long running processes, performing queries that do logical AND on multiple events or that negate an event are subject to a time window.