Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Will Splunk CIM be updated to include a "parent process hash" field for endpoints?

$
0
0
I am trying to ensure I align all logs field names to Splunk CIM but there is not a field for the "Hash of a parent process" under Endpoint - process table: https://docs.splunk.com/Documentation/CIM/4.13.0/User/Endpoint I have searched and could use "process_hash" or "file_hash" but these are already used for the running process so may confuse my correlations. For the time being I will use "**parent_process_hash**" to keep to the same naming convention unless some one tells me otherwise :-) Please let me know if there is a better way

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>