ASIM Process Terminate ASIM parser

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index


Parser Information

Property Value
Parser Name imProcessTerminate
Built-in Parser _Im_ProcessTerminate
Schema ProcessEvent
Schema Version 0.1.0
Parser Type 📦 Union (schema-level)
Parser Version 0.1.2 (version history)
Last Updated Feb 23, 2022
Source File Parsers\ASimProcessEvent\Parsers\imProcessTerminate.yaml

Description

This ASIM parser supports normalizing process terminate event logs from all supported sources to the ASIM ProcessEvent normalized schema.

Products

This union parser includes parsers for the following products:

Product Source Parser Solutions
Native _Im_ProcessEvent_Native SynqlyIntegrationConnector
VMware Carbon Black Cloud
_Im_ProcessTerminate_LinuxSysmon
_Im_ProcessTerminate_MD4IoT
_Im_ProcessTerminate_MicrosoftSecurityEvents
_Im_ProcessTerminate_MicrosoftSysmon
_Im_ProcessTerminate_MicrosoftWindowsEvents
_Im_ProcessTerminate_VMwareCarbonBlackCloud

Parameters

Name Type Default
starttime datetime datetime(null)
endtime datetime datetime(null)
commandline_has_any dynamic dynamic([])
commandline_has_all dynamic dynamic([])
commandline_has_any_ip_prefix dynamic dynamic([])
actingprocess_has_any dynamic dynamic([])
targetprocess_has_any dynamic dynamic([])
parentprocess_has_any dynamic dynamic([])
actorusername_has string *
dvcipaddr_has_any_prefix dynamic dynamic([])
dvchostname_has_any dynamic dynamic([])
eventtype string *

References


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to ASIM Index