After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline search requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID).These fields can be obtained from the ProcessRollup2 event, which contains information about processes that have executed on a host1.
Limited Time Offer
25%
Off
Laticia
2 days agoRyann
3 days agoMargart
5 days agoBettina
6 days agoEmerson
6 days agoEdison
9 days agoReuben
2 days agoAlonso
3 days agoJulene
4 days ago