Hi all,
Is there a possibility that when you've made a query with the hits you want, that also the next x amounts of events are being listed?
For example:
index=*_*_windows EventCode=4688 source=XmlWinEventLog:Security *[redacted]* host=[redacted] *schtasks.exe | table _time, TargetUserName, host, CommandLine, status
this will show exactly what I need to see, but I also want to know the next 10 events that occurred after the results of this query.
I hope this makes sense, if not clear don't hesitate to message me for clarification.
Many thanks in advance!
... View more