Hi, Can someone help me in correlating 4688 Process created and Logon 4624 events? I tried using the Transaction and Stats command but unable to get the proper results. When I use the Transaction command with Logon_ID field I could not able to correlate both 4624 and 4688 events. Can some one help me in fixing the query. (EventCode=4624 LogonType=3) OR ((EventCode=4688) | transaction Logon_ID host startswith="4624" endswith="4688" Can someone help me in getting the Correct field for Correlating the 4688 and 4624 events in splunk
... View more