Process Ingress Event
Vendor Documentation
Classification
Rule Name | Rule Type | Common Event | Classification |
---|---|---|---|
Process Ingress Event | Base Rule | Process/Service Startup Or Shutdown Activity | Startup and Shutdown |
Process Ingress Event : Start | Sub Rule | Process/Service Started | Startup and Shutdown |
Process Ingress Event : End | Sub Rule | Process/Service Stopped | Startup and Shutdown |
Mapping with LogRhythm Schema
Device Key in Log Message | LogRhythm Schema | Data Type |
vmid | <vmid> | Text/String |
command_line | <command> | Text/String |
computer_name | <dname> | Text/String |
md5 | <objectname> | Text/String |
parent_path | <parentprocesspath> | Text/String |
path | <process> | Text/String |
pid | <processid> | Number |
username | <domain> <account> | Text/String |