After pivoting to an event search from a detection, you locate the ProcessRollup2 event. Which two field values are you required to obtain to perform a Process Timeline search so you can determine what the process was doing?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the Process Timeline search requires two parameters:aid(agent ID) andTargetProcessId_decimal(the decimal value of the process ID).These fields can be obtained from the ProcessRollup2 event, which contains information about processes that have executed on a host1.
Limited Time Offer
25%
Off
Ryann
20 hours agoMargart
3 days agoBettina
4 days agoEmerson
4 days agoEdison
7 days agoAlonso
17 hours agoJulene
2 days ago