Open opliyal3 opened 1 year ago
I cannot recreate this issue. There is no actual filter function in pstree command, and the only difference between the two searches is should be after pstree has already returned the data, so seems like a Splunk issue.
I have seen issues with Splunk's garbage collection and the way Splunk distributes commands before. Could you try running the search after you table the tree? If that doesn't work and you want to send the search.log I can try to see if I can find any issues.
I use this query to filter process name
and got this return
but the original query
will be like it
How to do that, If I want to filter by process name, process id, command Thanks