You are reviewing the raw data in an event search from a detection tree. You find a FileOpenlnfo event and want to find out if any other files were opened by the responsible process. Which two field values do you need from this event to perform a Process Timeline search?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc2.The tool requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID)2.These fields can be obtained from any event that involves the process, such as a FileOpenInfo event, which contains information about a file being opened by a process2.
Elenore
8 days agoBeatriz
13 days agoChaya
18 days agoJosphine
24 days agoDalene
29 days agoSolange
1 month agoLemuel
1 month agoJeffrey
1 month agoFredric
2 months agoLeonardo
2 months agoCecily
2 months agoMalissa
2 months agoMerlyn
2 months agoEloisa
3 months agoHyun
4 months agoDerrick
4 months agoAfton
4 months agoVirgina
5 months agoLinsey
5 months agoQuentin
5 months agoDorathy
5 months agoTheola
5 months agoViki
5 months agoCordie
6 months agoTasia
6 months agoLarae
6 months ago