Dashboards & Visualizations

Any good Viz for process correlation

jbanAtSplunk
Communicator

Hi,

If I have process Events like

PID | ProcessName |  CommandLine | SpawnedByPID
100 | process_1 | process_1_commandLine | 99
101 | process_2 | process_2_commandLine | 100
200 | process_3 |  process_3_commandLine | 199
201 |  process_4 |  process_4_commandLine | 200

Is there any Viz that will map processes in some Folder/EDR like tree (where I can also click on node and get mora info).
For example, final results are based on PID but Viz looks like something like
| -> process_name_99
|----> process_1 (on hower or Click will get token process_1_commandLine)
|--------> process_2

| -> process_name_99
|----> process_3
|-------->process_4

Something like psTree just more advanced and connected by PID not names.

Labels (4)
0 Karma

_JP
Contributor

Sounds like you need this app from Splunkbase:

Treeview Viz | Splunkbase

Tags (1)
0 Karma

jbanAtSplunk
Communicator

It's good app but not good enough 😞 
Missing few additional fields. 

For example:
Parent_Process_Label (at least). <<< always Parent_Process_PID is "folder name". 

 

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...