Forum Discussion

Dark_Knight666's avatar
3 months ago
Solved

Elastic Data Ingest: Ep.1 – Auditbeat

Hello, I'm stuck on Q11 of this lab and would greatly appreciate some help, please. I'm a little confused as to how to go about answering the question? If I use the filter for - Processhash.sha1 IS ...
  • neeemu's avatar
    neeemu
    3 months ago

    You're provided the Process PID in the tasks so searching for that returns event for that process. Expanding that event will show further details, one of which is the SHA1 hash.