ASIM Process Event filtering parser

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index


Parser Information

Property Value
Parser Name imProcessEvent
Built-in Parser _Im_ProcessEvent
Schema ProcessEvent
Schema Version 0.1.0
Parser Type 📦 Union (schema-level)
Parser Version 0.1.3 (version history)
Last Updated June 3, 2024
Source File Parsers\ASimProcessEvent\Parsers\imProcessEvent.yaml

Description

This ASIM parser supports normalizing process event logs from all supported sources to the ASIM ProcessEvent normalized schema.

Products

This union parser includes parsers for the following products:

Product Source Parser Solutions
_Im_ProcessCreate_LinuxSysmon
_Im_ProcessCreate_MD4IoT
_Im_ProcessCreate_MicrosoftSecurityEvents
_Im_ProcessCreate_MicrosoftWindowsEvents
SentinelOne _Im_ProcessCreate_SentinelOne
_Im_ProcessCreate_VMwareCarbonBlackCloud
Sysmon _Im_ProcessEvent_CreateMicrosoftSysmon
Sysmon _Im_ProcessEvent_CreateMicrosoftSysmonWindowsEvent Windows Forwarded Events
Microsoft 365 Defender for endpoint _Im_ProcessEvent_Microsoft365D
Native _Im_ProcessEvent_Native SynqlyIntegrationConnector
VMware Carbon Black Cloud
_Im_ProcessTerminate_LinuxSysmon
_Im_ProcessTerminate_MD4IoT
_Im_ProcessTerminate_MicrosoftSecurityEvents
_Im_ProcessTerminate_MicrosoftSysmon
_Im_ProcessTerminate_MicrosoftSysmonWindowsEvent
_Im_ProcessTerminate_MicrosoftWindowsEvents
_Im_ProcessTerminate_VMwareCarbonBlackCloud

Parameters

Name Type Default
starttime datetime datetime(null)
endtime datetime datetime(null)
commandline_has_any dynamic dynamic([])
commandline_has_all dynamic dynamic([])
commandline_has_any_ip_prefix dynamic dynamic([])
actingprocess_has_any dynamic dynamic([])
targetprocess_has_any dynamic dynamic([])
parentprocess_has_any dynamic dynamic([])
actorusername_has string *
targetusername_has string *
dvcipaddr_has_any_prefix dynamic dynamic([])
dvchostname_has_any dynamic dynamic([])
hashes_has_any dynamic dynamic([])
eventtype string *

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index