Hello I would have 2 questions :
-
In an event id 1 (pcoess creation), what is the difference between the field winlog.process.pid (eg 2360) and the field process.pid (eg 6392) ?
-
Why did not the command "C:\Windows\System32\xcopy.exe" /s /i /e /h D:\review.dat C:\Users\EVAN~1.HUT\AppData\Local\Temp\review.dat" trigger an event id 11 ?
Cheers