You can jump to a Process Timeline from many views, like a Hash Search, by clicking which of the following?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline tool allows you to view all cloudable events associated with a given process, such as process creation, network connections, file writes, registry modifications, etc1.The tool requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID)1.You can jump to a Process Timeline from many views, such as Hash Search, Host Timeline, Event Search, etc., by clicking on either the Process ID or Parent Process ID fields in those views1.This will automatically populate the aid and TargetProcessId_decimal parameters for the Process Timeline tool1.
Valentin
4 days agoSabra
9 days agoDion
14 days agoCrista
20 days agoBrice
25 days agoKattie
30 days agoClaribel
1 month agoJanna
1 month agoAshlyn
2 months agoElbert
2 months agoDenny
2 months agoTamesha
3 months agoLavonne
3 months agoSolange
3 months agoSherman
3 months ago