Active Response search syntax for pulling up a machine name
I'm trying to figure out different search syntax command that I can run in the active response search. I would like to get the command for searching for a particular machine name so then I can perform a reaction on it (quarantine, shutdown the OS etc.)
I tried the following search commands and was unsuccessful.
hostinfo hostname equals “PCNAME”
HostInfo where HostInfo hostname equals “PCNAME”
and I was trying to use the following using the autofill/predictive commands and got this one, but it didn't work either.
HostInfo hostname where HostInfo hostname equals “PCNAME”
If anybody can provide other useful active response search commands that they use that would also be helpful. I've been going through the product guide and trying other commands, but it's still a bit foreign to me. Would someone be able to provide the syntax for getting a list of machines that had connected to a certain host or IP address?
Re: Active Response search syntax for pulling up a machine name
The syntax you are looking for here should be simiilar to what you have been trying:
HostInfo hostname where HostInfo hostname equals bbepo59
The case of the letters is important here. The first "HostInfo hostname" is advising the query engine that in the output you are only interested in seeing the hostname returned. You can add additional columns to the return with a comma, ex :
HostInfo hostname, ipaddress where HostInfo hostname equals bbepo59
Or you can opt to return all the data the HostInfo collector returns:
HostInfo where HostInfo hostname equals bbepo59
I hope this is helpful and starts to produce some actionable results for you.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.