All Apps and Add-ons

Will Splunk CIM be updated to include a "parent process hash" field for endpoints?

sethbrunt
Observer

I am trying to ensure I align all logs field names to Splunk CIM but there is not a field for the "Hash of a parent process" under Endpoint - process table:

https://docs.splunk.com/Documentation/CIM/4.13.0/User/Endpoint

I have searched and could use "process_hash" or "file_hash" but these are already used for the running process so may confuse my correlations.

For the time being I will use "parent_process_hash" to keep to the same naming convention unless some one tells me otherwise 🙂

Please let me know if there is a better way

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...