What does pivoting to an Event Search from a detection do?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, pivoting to an Event Search from a detection takes you to the raw Insight event data and provides you with a number of Event Actions1.Insight events are low-level events that are generated by the sensor for various activities, such as process executions, file writes, registry modifications, network connections, etc1.You can view these events in a table format and use various filters and fields to narrow down the results1.You can also select one or more events and perform various actions, such as show a process timeline, show a host timeline, show associated event data, show a +/- 10-minute window of events, etc1.These actions can help you investigate and analyze events more efficiently and effectively1.
Keva
21 days agoBeatriz
27 days agoAfton
1 month agoSharee
1 month agoLonny
1 month agoAmmie
2 months agoDaisy
3 months agoLoren
3 months agoBong
4 months agoBrittani
4 months agoEladia
4 months agoReita
5 months ago