All Apps and Add-ons

Will Splunk CIM be updated to include a "parent process hash" field for endpoints?

sethbrunt
Observer

I am trying to ensure I align all logs field names to Splunk CIM but there is not a field for the "Hash of a parent process" under Endpoint - process table:

https://docs.splunk.com/Documentation/CIM/4.13.0/User/Endpoint

I have searched and could use "process_hash" or "file_hash" but these are already used for the running process so may confuse my correlations.

For the time being I will use "parent_process_hash" to keep to the same naming convention unless some one tells me otherwise 🙂

Please let me know if there is a better way

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...