VMware Carbon Black EDR 7.5 User Guide Advanced Search Queries
17
Searches for any of these strings will match on the binary. Phrase queries for any two
consecutive terms also match on the binary.
For example:
product_name: "visual studio"
count
An integer value. If it exists, the values are from 0 to MAXINT. It supports two types of
search syntaxes:
• X: Matches all fields with precisely X. For example, modload_count:34 for
processes with exactly 34 modloads.
• [X TO Y]: Matches all fields with counts >= X and <= Y. For example,
modload_count:[1 TO 10] for processes with 1 to 10 modloads.
In both cases, either X or Y can be replaced by the wildcard *. For example:
netconn_count:* for any process where the netconn_count field exists.
netconn_count:[10 TO *] for any process with more than 10 network connections.
datetime
Datetime fields have five types of search syntaxes:
• YYYY-MM-DD matches all entries on this day, for example, start:2016-12-01 for
all processes started on Dec 1, 2016.
• YYYY-MM-DDThh:mm:dd matches all entries within the next 24 hours from this date
and time, for example, start:2016-12-01T22:15:00 for all processes started
between Dec 1, 2016 at 22:15:00 to Dec 2, 2016 at 22:14:59.
• [YYYY-MM-DD TO YYYY-MM-DD] matches all entries between, for example,
start:[2016-12-01 TO 2016-12-31] for all processes started in Dec 2016.
• [YYYY-MM-DDThh:mm:ss TO YYYY-MM-DDThh:mm:ss] matches all entries
between, for example, start:[2016-12-01T22:15:00 TO 2016-12-
01:23:14:59] for all processes started in Dec 1, 2016 within the given time frame.
• -Xh relative time calculations matches all entries with a time between NOW-10h and
NOW. Support units supported are h: hours, m: minutes, s: seconds as observed on
the host, for example, start:-24h for all processes started in the last 24 hours.
As with counts, YYYYMMDD can be replaced the wildcard *, for example, start:[2016-
01-01 TO *] for any process started after 1 Jan 2016.
keyword
Keywords are text fields with no tokenization. The term that is searched for must
exactly match the value in the field, for example, process_name:svchost.exe.