Go to investigate page; processes tab:
these queries return the expected results:
process_cmdline:c\:\\windows\\system32\\msiexec.exe process_cmdline:c\:\\windows\\system32\\.exe (finds all *.exe processes as it should)but the wildcard with process_cmdline is NOT returning any hits (no syntax error but no hits):
process_cmdline:c\:\\windows\\system32\\*.exe process_cmdline:c\:\\windows\\system32\\\*.exe process_cmdline:c\:\\windows\\system32\\msi*.exe process_cmdline:c\:\\windows\\system32\\msi\*.exe process_cmdline:c\:/\windows/\system32/\msi*.exe
process_cmdline:c\:\ windows\ system32\ msiex*