Which of the following queries will return the parent processes responsible for launching badprogram exe?
This query will return the parent processes responsible for launching badprogram.exe by using a subsearch to find the processrollup2 events where FileName is badprogram.exe, then renaming the TargetProcessld_decimal field to ParentProcessld_decimal and using it as a filter for the main search, then using stats to count the occurrences of each FileName by _time. The other queries will either not return the parent processes or use incorrect field names or syntax.
Sharen
14 days agoMartha
19 days agoSharen
21 days agoRyan
1 months agoJannette
1 months agoSelma
20 days agoMartha
1 months agoTennie
1 months agoVeta
24 days agoLawrence
27 days agoLeota
29 days ago