You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc2.The tool requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID)2.These fields can be obtained from any event that involves the process, such as a FileOpenInfo event, which contains information about a file being opened by a process2.
Fredric
4 days agoLeonardo
9 days agoCecily
14 days agoMalissa
19 days agoMerlyn
25 days agoEloisa
30 days agoHyun
2 months agoDerrick
3 months agoAfton
3 months agoVirgina
3 months agoLinsey
3 months agoQuentin
3 months agoDorathy
4 months agoTheola
4 months agoViki
4 months agoCordie
4 months agoTasia
4 months agoLarae
4 months ago