Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sharen
4 months agoMartha
4 months agoSharen
4 months agoRyan
4 months agoJannette
5 months agoRory
3 months agoJosephine
3 months agoSelma
4 months agoMartha
5 months agoTennie
5 months agoVeta
4 months agoLawrence
4 months agoLeota
4 months ago