Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sheron
29 days agoIvory
1 month agoTiera
1 month agoMose
1 month agoTandra
2 months agoAnnamae
2 months agoFrederic
2 months agoMerlyn
2 months agoTayna
2 months agoMargart
3 months agoRana
3 months agoLoren
3 months ago