Using the "virustotal" cmd and it appears that if there are multiple events that have the same file_hash that only one of the events will "populate" the field/values from the virustotal cmd. I can't post events.
Example would be:
event 1:
_time=08/06/2023 07:00:00
dest=abc1
file_hash=45vv678
file_name=badguy.dll
file_path=my_path
vt_* will be populated
event 2:
_time=08/06/2023 07:150:00
dest=abc2
file_hash=45vv678
file_name=badguy.dll
file_path=my_path
vt_* - nothing will be populated
event 3:
_time=08/06/2023 07:30:00
dest=abc3
file_hash=45vv678
file_name=badguy.dll
file_path=my_path
vt_* - nothing will be populatedI know the spl is fine as if I were to change the time picker to that of just the 2nd or 3rd event, all the vt_ fields would be populated. It looks like this is the expected behavior. Thanks in advance.
There is no virustotal command in Search Commands. If you are using a special app that provides this command, you should go to that app's forum for help.