I am trying to ensure I align all logs field names to Splunk CIM but there is not a field for the "Hash of a parent process" under Endpoint - process table:
https://docs.splunk.com/Documentation/CIM/4.13.0/User/Endpoint
I have searched and could use "process_hash" or "file_hash" but these are already used for the running process so may confuse my correlations.
For the time being I will use "**parent_process_hash**" to keep to the same naming convention unless some one tells me otherwise :-)
Please let me know if there is a better way
↧