- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
faisalzabd
Engager
01-16-2024
11:33 PM
I'm trying to look for refernce or documintation that shows me which fields in sysmon logs should be mapped to which fields in endpoint datamodel.
for example Image & ParentImage it should show in which fields from endpoint datamodel since we have multiple fields for processes and parent processes it is confusing.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-17-2024
08:09 AM
The CIM manual should help. It describes each DM field so you can determine which of the fields in your data map best. See https://docs.splunk.com/Documentation/CIM/5.3.1/User/Endpoint#Processes
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-17-2024
08:09 AM
The CIM manual should help. It describes each DM field so you can determine which of the fields in your data map best. See https://docs.splunk.com/Documentation/CIM/5.3.1/User/Endpoint#Processes
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
