Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sharen
2 months agoMartha
2 months agoSharen
2 months agoRyan
3 months agoJannette
3 months agoRory
2 months agoJosephine
2 months agoSelma
2 months agoMartha
3 months agoTennie
3 months agoVeta
3 months agoLawrence
3 months agoLeota
3 months ago