Splunk Enterprise Security

How to know the correlation search query and time range conditions for two of these use cases?

Ash
Engager

Please let me know the correlation search query and time range conditions for two of these usecases. I have windows powershell logs onboarded.

 

1. Suspicious Windows Shell Launched by Web Applications 

2. Suspicious Windows Shell Launched by a trusted process

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...