Skip to content

[Enhancement] Add process.args_count to process events #14767

@w0rk3r

Description

@w0rk3r

For compatibility with detection rules and parity with other datasets, we should add process.args_count to process events that have command_line populated in both Windows and System integrations.

PS: Sysmon logs collected via Windows Integration already have this field. This only needs to be added to Forwarded logs.

Metadata

Metadata

Assignees

No one assigned
    No fields configured for Enhancement.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions