Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Tandra
4 days agoAnnamae
9 days agoFrederic
14 days agoMerlyn
20 days agoTayna
25 days agoMargart
30 days agoRana
1 month agoLoren
1 month ago