Process Log
Normalize process logs in Genian EDR.
Type | Field | Display Name |
---|---|---|
DATE | _time | Time |
STRING | event_type | Event Type |
STRING | event_subtype | Event Subtype |
INT | important | Important level |
IP | host_ip | Host IP |
STRING | nt_domain | NT domain |
STRING | hostname | Hostname |
STRING | tag | Tag |
STRING | cmd_line | Command line |
STRING | req_image | Request process name |
STRING | parent_image | Parent process name |
STRING | image | Process name |
STRING | image_path | Process path |
STRING | file_name | File name |
STRING | file_path | File path |
DATE | file_ctime | File creation time |
DATE | file_mtime | File modification time |
STRING | md5 | MD5 |
STRING | sha256 | SHA256 |
STRING | logon_id | Logon ID |
INT | session_id | Session ID |
STRING | proc_user_id | Process user ID |
INT | req_pid | Request PID |
INT | ppid | Parent PID |
INT | pid | PID |
INT | child_pid | Child PID |
STRING | req_pguid | Request process GUID |
STRING | parent_pguid | Parent process GUID |
STRING | pguid | Process GUID |
STRING | child_pguid | Child process GUID |
STRING | device_id | Device ID |
LONG | event_seq | Event sequence |
STRING | driver_type | Driver type |
STRING | file_type | File type |
STRING | file_ext | File extension |
STRING | file_attr | File attribute |
BOOL | exit_flag | Is process terminated |
DATE | exit_time | Process termination time |
BOOL | is_system | Is system process |
STRING | integrity_level | Integrity level |
INT | interactive_flag | Is interactive process |
LONG | parent_proc_event_seq | Parent process event sequence |
LONG | req_event_seq | Request event sequence |
STRING | trunk_id | Trunk process ID |
STRING | trunk_idx | Trunk process IDX |
STRING | info_title | Info title |
STRING | info | Info details |