Agreed with sbag0024. The correct answer is 'B'. When investigating a detection, there will be a magnifying glass icon. Hovering and selecting 'Event Search' will open the Splunk equivalent search engine, exposing all of the raw data from the 'aid' and 'treeIdDecimal'.
The answer is B. When you click on Full Detection data and then the 3 dots, you can pivot to Event Seach where you land on the raw data info where you can select "Event Actions" which there are a number of them to select. Going with B
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alanalanalan
6 months agojdilliway
9 months, 3 weeks agosbag0024
9 months, 3 weeks agowildbandana
11 months, 2 weeks agojdilliway
9 months, 3 weeks ago