Hi team,
I have security events and process events get indexed to SPLUNK instance from windows...
How to get to know under which process which user is running....
That is how to integrate security events and process events and get statistics for the user who logged in to the server...