Im trying to get the root process for an event on a client currently offline. Using Data Lake query.
However, the Parent PID Search gives no results.The Event is 14 days old. I thought the Sophos PID is THE idicator of something in the Data Lake - how can it be missing?
In an other case, if I search for the Process Path I was looking fore above and select
I get a weird error message:
Invalid operation due to 'Query failed (#20211102_160842_00203_c2dxd): Loaded block positions count (945) doesn't match lazy block positions count (1024)'
I'd like to use this feature but I stumble across missing data much too often.
This thread was automatically locked due to age.