When examining raw event data, what is the purpose of the field called ParentProcessld_decimal?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, the ParentProcessld_decimal field contains the decimal value of the process ID of the parent process that spawned or injected into the target process1.This field can be used to trace the process lineage and identify malicious or suspicious activities1.
Currently there are no comments in this discussion, be the first to comment!