Skip to content

Commit 7a214c4

Browse files
authored
Merge pull request #3522 from splunk/extra_field_removal
Removing duplicate creation of user
2 parents c599382 + 57fddbf commit 7a214c4

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

detections/endpoint/first_time_seen_child_process_of_zoom.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: First Time Seen Child Process of Zoom
22
id: e91bd102-d630-4e76-ab73-7e3ba22c5961
3-
version: 7
4-
date: '2025-05-02'
3+
version: 8
4+
date: '2025-05-15'
55
author: David Dorsey, Splunk
66
status: experimental
77
type: Anomaly
@@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
2626
as process_exec values(Processes.process_guid) as process_guid values(Processes.process_hash)
2727
as process_hash values(Processes.process_integrity_level) as process_integrity_level
2828
values(Processes.process_name) as process_name values(Processes.process_path) as
29-
process_path values(Processes.user) as user values(Processes.user_id) as user_id
29+
process_path values(Processes.user_id) as user_id
3030
values(Processes.vendor_product) as vendor_product from datamodel=Endpoint.Processes
3131
where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us)
3232
by Processes.process_id Processes.dest | `drop_dm_object_name(Processes)` | lookup

0 commit comments

Comments
 (0)