Process Ingress Event

Vendor Documentation


Classification

Rule Name

Rule Type

Common Event

Classification

Process Ingress Event

Base Rule

Process/Service Startup Or Shutdown Activity

Startup and Shutdown

Process Ingress Event : Start

Sub Rule

Process/Service Started

Startup and Shutdown

Process Ingress Event : End

Sub Rule

Process/Service Stopped

Startup and Shutdown

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

vmid

<vmid>

Text/String

command_line

<command>

Text/String

computer_name

<dname>

Text/String

md5

<objectname>
<hash>

Text/String

parent_path

<parentprocesspath>
<parentprocessname>

Text/String

path

<process>

Text/String

pid

<processid>

Number

username

<domain>

<account>

Text/String