The Investigate page lets you specify a search query. When building your query, you can encounter the
enriched search field as a suggestion. Use the improved
enriched field to find all enriched sensor data (determined to be of interest based on types of behavior that can be associated with malicious activity) by the Carbon Black Cloud Analytics engine. When set to
true, this field contributes to more accurate search results in the Processes tab. The Enriched Events tab lists enriched events without the need to specify
enriched:true in the search query.
You can limit the results to only enriched data from the Carbon Black Cloud Endpoint Standard-enabled sensors by including the
enriched:true as part of your search query. To include only non-enriched data, add the
-enriched:true to your search. The Investigate search interface no longer accepts the
legacy:true searchable field. You must use the
enriched field instead.
To be able to take advantage of the enriched data, enable the Carbon Black Cloud Endpoint Standard and the Carbon Black Cloud Enterprise EDR solutions.
-enriched:true. You can thereby minimize the false positives and negatives.
IOC query excluding enriched data: