Environment
Question
Why do queries and watchlists using child negation still showing hits with parents and with the negated child processes?
Answer
- The watchlist only searches within a one-hour time window for the child process search condition to be met.
- This can result in what looks to be inaccurate hits when long-lived processes are searched on.
- The one-hour window and these search results also applies to long-lived processes and searching with multiple conditions.
Additional Notes
Related Content