splunk / TA-microsoft-365-defender-advanced-hunting-add-on

13 stars 7 forks source link

Change fieldalias process_name to properties.FileName #3

Closed thilles closed 3 years ago

thilles commented 3 years ago

properties.FileName contains fewer NULL values than properties.ProcessVersionInfoOriginalFileName

inspired commented 3 years ago

Will likely need to adjust process_exec and process too. Will fix