The grid displays the events collected by the Process Tracker module. Each row in this table contains a process execution event. For more information, see Unique process execution. The following table describes each column in the grid. The grid displays 50 events per page.
Column | Description | Notes |
|---|---|---|
Agent ID | The unique system-generated ID for the host endpoint that reported the event. | |
Alerted At | Time stamp of the associated alert, if one was generated. | |
Args | The command arguments supplied to the process when it executed. | |
Attributes | Attributes associated with the process file. Possible values include the following:
| Only available on Windows |
Creation Time | The creation time of the process file. | Not available on Linux |
Enrichment Status | The status from the enrichment workflow, if enabled. Possible values include the following:
| |
Event At | The time stamp for when the process execution was detected on the endpoint. | |
File Size (Bytes) | The size of the file associated with the process. | |
Group | The name of the user group associated with the process file. | Not available on Windows |
Hostname | The hostname of the endpoint. | |
Index | The ordinal of the event as it was received by the Process Tracker Module. | |
Is Prelinked | The file associated to the process was prelinked. Enrichment of prelinked files is not supported. | Only available on Linux distributions that support prelinking. |
Is Signed | Whether the file associated to the process is signed. Yes or No. | Only available on Windows |
Last Accessed Time | The last access time of the process file. | May not be available on some Windows versions |
Last Status Change Time | The last metadata update time of the process file. | Not available on Windows |
MD5 | The MD5 hash of the process file. | |
Modified Time | The time for last content modification of the process file. | |
Owner | The owner associated to the process file. | |
Parent Path | The fully qualified path of the file associated with the parent process of the process being executed. | |
Parent PID | The process ID of the parent process. | |
PID | The process ID of the process that was executed. | |
Process File Cert | Certificate details, if the process file was signed. The following are possible values:
| Only available on Windows |
Process File Exists | Whether the associated process file existed on disk at the time that the event was detected. Yes or No. | |
Process Path | The fully qualified path of the file associated with the process. | |
Signature Verified | Whether a verified signature exists for the file associated to the process. Yes or No. | Only available on Windows |
Start Time | The time that the process started execution on the endpoint. | |
Type | This event is a start or stop event. Stop events are only issued for processes when an associated start event was not detected. | |
User | The ID of the user who launched the process. |
For each column in the grid, you can apply a filter that will show only the rows that match your criteria. You can filter on more than one column at a time, according to the information that you are seeking to reveal. Your filter settings can be saved and recalled by using the Filter Sets tool.
The rows in the grid can be sorted in ascending and descending order on most columns. Columns that can be sorted have an
button to the right of the column name in the header. A sort cannot be applied to more than one column at a time.