I'm trying to look for refernce or documintation that shows me which fields in sysmon logs should be mapped to which fields in endpoint datamodel.
for example Image & ParentImage it should show in which fields from endpoint datamodel since we have multiple fields for processes and parent processes it is confusing.
The CIM manual should help. It describes each DM field so you can determine which of the fields in your data map best. See https://docs.splunk.com/Documentation/CIM/5.3.1/User/Endpoint#Processes
The CIM manual should help. It describes each DM field so you can determine which of the fields in your data map best. See https://docs.splunk.com/Documentation/CIM/5.3.1/User/Endpoint#Processes