I am having a file with windows security logs . a column has data with the process name that ran on the machine
The output is below . I only need the part that comes after New Process Name, in this case C:\Windows\SysWOW64\notepad.exe extracted and placed in next column. all other data should be removed.
____________________________
A new process has been created.
Subject:
Security ID: SYSTEM
Account Name: machinename
Account Domain: domainame
Logon ID: 0x232
Process Information:
New Process ID: 0x134823
New Process Name: C:\Windows\SysWOW64\notepad.exe
Token Elevation Type: TokenElevationTypeDefault (1)
Creator Process ID: 0x238497
Bookmarks