Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sharen
5 days agoMartha
10 days agoSharen
12 days agoRyan
22 days agoJannette
24 days agoSelma
11 days agoMartha
26 days agoTennie
28 days agoVeta
15 days agoLawrence
18 days agoLeota
20 days ago