Genian EDR

Download 27
Last updated Aug 6, 2023

Process Log

Normalize process logs in Genian EDR.

TypeFieldDisplay Name
DATE_timeTime
STRINGevent_typeEvent Type
STRINGevent_subtypeEvent Subtype
INTimportantImportant level
IPhost_ipHost IP
STRINGnt_domainNT domain
STRINGhostnameHostname
STRINGtagTag
STRINGcmd_lineCommand line
STRINGreq_imageRequest process name
STRINGparent_imageParent process name
STRINGimageProcess name
STRINGimage_pathProcess path
STRINGfile_nameFile name
STRINGfile_pathFile path
DATEfile_ctimeFile creation time
DATEfile_mtimeFile modification time
STRINGmd5MD5
STRINGsha256SHA256
STRINGlogon_idLogon ID
INTsession_idSession ID
STRINGproc_user_idProcess user ID
INTreq_pidRequest PID
INTppidParent PID
INTpidPID
INTchild_pidChild PID
STRINGreq_pguidRequest process GUID
STRINGparent_pguidParent process GUID
STRINGpguidProcess GUID
STRINGchild_pguidChild process GUID
STRINGdevice_idDevice ID
LONGevent_seqEvent sequence
STRINGdriver_typeDriver type
STRINGfile_typeFile type
STRINGfile_extFile extension
STRINGfile_attrFile attribute
BOOLexit_flagIs process terminated
DATEexit_timeProcess termination time
BOOLis_systemIs system process
STRINGintegrity_levelIntegrity level
INTinteractive_flagIs interactive process
LONGparent_proc_event_seqParent process event sequence
LONGreq_event_seqRequest event sequence
STRINGtrunk_idTrunk process ID
STRINGtrunk_idxTrunk process IDX
STRINGinfo_titleInfo title
STRINGinfoInfo details