Hi guys,
I have a query that works and gives me table such as below. What I wanted to do was when count of values in Field1 and Field2 is greater than 1, exclude it.
In other words, if combination of svchost and services.exe is seen more than once, exclude it. In this case, we see it twice, so we want to exclude it from results? How could I do this?
I tried but I am not getting my head around this one. Thanks for your help in advance.
Field1 | Field2 | Field3 |
svchost | services.exe | c:\windows\system32 |
rdp.exe | cmd.exe | c:\windows\system32 |
svchost | services.exe | c:\windows\system32 |
wmic.exe | powershell.exe | c:\windows\system32 |
| eventstats count by Field1 Field2
| where count = 1