We are having issues with our Splunk datamodel Endpoint Processes.process_name. The current value for Process.process_name is...
case(isnotnull(process) AND parent_process!="",replace(process,".*\\\\(.*)","\1"),1=1,"unknown")
The regex pulls correct and invalid results as follows...
Correct:
lsass.exe
NmService.exe
Microsoft.IdentityServer.ServiceHost.exe
Incorrect:
AppxData.csv"
BackgroundTaskHost.exe" -ServerName:BackgroundTaskHost.WebAccountProvider
RuntimeBroker.exe -Embedding
The correct results show the actual process name while the incorrect ones may not show the process name or shows the process name with an extra quotation mark or command line arguments.
How do we fix the regex to only show process name?