All Apps and Add-ons

Will Splunk CIM be updated to include a "parent process hash" field for endpoints?

New Member

I am trying to ensure I align all logs field names to Splunk CIM but there is not a field for the "Hash of a parent process" under Endpoint - process table:

I have searched and could use "process_hash" or "file_hash" but these are already used for the running process so may confuse my correlations.

For the time being I will use "parent_process_hash" to keep to the same naming convention unless some one tells me otherwise 🙂

Please let me know if there is a better way

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.