Feed Query : Process Hit

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Feed Query : Process Hit

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

cmdline

<command>

Text/String

feed_name

<sender>

Text/String

group

<group>

Text/String

hostname

<dname>

Text/String

interface_ip

<sip>

IP Address

digsig_result

<result>

Text/String

parent_name

<parentprocessname>

Text/String

parent_pid

<parentprocessid>

Number

path

<process>

Text/String

process_md5

<objectname>

Text/String

process_md5

<hash>

Text/String

process_name

<object>

Text/String