uberAgent collects detailed process stop information like the process name, the process lifetime as well as the parent process.
uberAgentESA:Process:ProcessStop
ProcessStop
1
2
3
4
HashTypeDisplayName
coalesce (ProcUserExpanded, ProcUser)
ProcUser
_time
lookup_hash_types
MD5
SHA-1
SHA-256
ImpHash
Your email address will not be published. Required fields are marked *
Comment
Name *
Email *
Website
Process Stop Metrics
In this article
Process Stop
uberAgent collects detailed process stop information like the process name, the process lifetime as well as the parent process.
Details
uberAgentESA:Process:ProcessStop
ProcessStop
List of Fields in the Raw Agent Data
1
,2
,3
or4
. See alsoHashTypeDisplayName
List of Calculated Fields
coalesce (ProcUserExpanded, ProcUser)
ProcUser
_time
* 1000lookup_hash_types
. Can beMD5
,SHA-1
,SHA-256
orImpHash
.