I have an index that contain security evevts from endpoints.
In the index there is event 4688 (process creation) and 4689 (process termination).
There are the fields : event_id, process_name.
I want to find all of the 4689 events that occurred at the 20 seconds after the creation of event 4688 with process_name :"XXXX" on the same computer.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.