Hello,
I am working in the subject lab - “Valid Accounts: Local Accounts” - Part 2 in Elastic. In step 6,
In the Search field, type event.code : 4688 AND process.name : net.exe and click the Update button to search for Windows Event 4688 “A new process have been created” where net.exe was executed. However, ELS does not recognize the search criteria. I typed this criteria several times and even tried variations. But still no luck. Why is this happening? Please advise. I have added a screenshot for your review.
Thank you.


