How-To: Add ComputerName or UserName to Falcon search results

Not every Falcon Data Replicator (FDR) event includes a ComputerName or UserName field by default - however, it's possible to add those fields at the time of your query.

Version 1.1.1 of the FDR package includes a scheduled search that creates a .CSV lookup file every 3 hours, and can be used to look up the ComputerName via the aid field and the match() function. It's located at the Files menu at the top of the LogScale UI - if the scheduled search is running as expected, the file will be named fdr_aidmaster.csv.