So these entries are taken from 5 separate events. What I would need is to extract to separate fields from the lines above “processpath” and “process”. So the “processpath” would indicate the path where the process starts (e.g. C:\Windows\System32\) and the “process” field would indicate the process itself (e.g. cscript.exe).