I have an index that contain security evevts from endpoints.
In the index there is event 4688 (process creation) and 4689 (process termination).
There are the fields : event_id, process_name.
I want to find all of the 4689 events that occurred at the 20 seconds after the creation of event 4688 with process_name :"XXXX" on the same computer.
Is it possible to do this?