For compatibility with detection rules and parity with other datasets, we should add process.args_count to process events that have command_line populated in both Windows and System integrations.
PS: Sysmon logs collected via Windows Integration already have this field. This only needs to be added to Forwarded logs.
For compatibility with detection rules and parity with other datasets, we should add
process.args_countto process events that have command_line populated in both Windows and System integrations.PS: Sysmon logs collected via Windows Integration already have this field. This only needs to be added to Forwarded logs.