Process Log
Normalize process logs in Genian EDR.
| Type | Field | Display Name |
|---|---|---|
| DATE | _time | Time |
| STRING | event_type | Event Type |
| STRING | event_subtype | Event Subtype |
| INT | important | Important level |
| IP | host_ip | Host IP |
| STRING | nt_domain | NT domain |
| STRING | hostname | Hostname |
| STRING | tag | Tag |
| STRING | cmd_line | Command line |
| STRING | req_image | Request process name |
| STRING | parent_image | Parent process name |
| STRING | image | Process name |
| STRING | image_path | Process path |
| STRING | file_name | File name |
| STRING | file_path | File path |
| DATE | file_ctime | File creation time |
| DATE | file_mtime | File modification time |
| STRING | md5 | MD5 |
| STRING | sha256 | SHA256 |
| STRING | logon_id | Logon ID |
| INT | session_id | Session ID |
| STRING | proc_user_id | Process user ID |
| INT | req_pid | Request PID |
| INT | ppid | Parent PID |
| INT | pid | PID |
| INT | child_pid | Child PID |
| STRING | req_pguid | Request process GUID |
| STRING | parent_pguid | Parent process GUID |
| STRING | pguid | Process GUID |
| STRING | child_pguid | Child process GUID |
| STRING | device_id | Device ID |
| LONG | event_seq | Event sequence |
| STRING | driver_type | Driver type |
| STRING | file_type | File type |
| STRING | file_ext | File extension |
| STRING | file_attr | File attribute |
| BOOL | exit_flag | Is process terminated |
| DATE | exit_time | Process termination time |
| BOOL | is_system | Is system process |
| STRING | integrity_level | Integrity level |
| INT | interactive_flag | Is interactive process |
| LONG | parent_proc_event_seq | Parent process event sequence |
| LONG | req_event_seq | Request event sequence |
| STRING | trunk_id | Trunk process ID |
| STRING | trunk_idx | Trunk process IDX |
| STRING | info_title | Info title |
| STRING | info | Info details |