Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sharen
2 months agoMartha
2 months agoSharen
2 months agoRyan
2 months agoJannette
2 months agoRory
1 months agoJosephine
1 months agoSelma
2 months agoMartha
2 months agoTennie
2 months agoVeta
2 months agoLawrence
2 months agoLeota
2 months ago