Closed Moofeng closed 2 years ago
Just as the example here
How can I add more metadata to the result such like
index=sysmon EventCode=1 host=victim_machine | fields * | pstree child=Image parent=ParentImage | table _time, host, tree
Well, I've got the trick
Just as the example here
How can I add more metadata to the result such like