SPL (Splunk) eval statements can be used to convert Unix times (Epoch) into UTC readable time Which eval function is correct^
The Agent ID (AID) and the Target Process ID are the elements that are required to properly execute a Process Timeline. The Agent ID (AID) is a unique identifier for each host that has a Falcon sensor installed. The Target Process ID is the decimal representation of the process identifier for the process that you want to investigate. These two elements are used to query the cloud for the events related to the process on the host. The Agent ID (AID) only, the Hostname and Local Process ID, and the Target Process ID only are not sufficient to execute a Process Timeline.
Yoko
14 days agoDana
16 days agoPaulina
17 days agoPamela
19 days agoZoila
20 days agoRanee
1 days agoJerry
4 days agoHolley
20 days agoRoyce
22 days agoTayna
25 days agoDomingo
26 days agoTayna
1 months ago