removed unecessary extend
This commit is contained in:
Родитель
6f267e49f8
Коммит
c31d1cdd79
|
@ -28,7 +28,6 @@ query: |
|
|||
| where ParentProcessName hassuffix "w3wp.exe"
|
||||
| extend ProcessHost = strcat(Process, "-", Computer)
|
||||
| where ProcessHost !in (known_procs)
|
||||
| extend timekey = bin(TimeGenerated, 1h)
|
||||
| project-reorder TimeGenerated, Computer, NewProcessName, ParentProcessName, Account, NewProcessId
|
||||
| extend timestamp = TimeGenerated, HostCustomEntity = Computer, AccountCustomEntity = Account
|
||||
entityMappings:
|
||||
|
|
Загрузка…
Ссылка в новой задаче