Hey @ll
I don't understand why this query is not bringing any results
data.win.eventdata.parentImage: "C:\Windows\explorer.exe"
or
data.win.eventdata.parentImage: "explorer.exe"
data is there...
Thank you!
Hey @ll
I don't understand why this query is not bringing any results
data.win.eventdata.parentImage: "C:\Windows\explorer.exe"
or
data.win.eventdata.parentImage: "explorer.exe"
data is there...
Thank you!
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.