[crowdstrike] Prefer ImageFileName for the value of process.executable #8322
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Proposed commit message
Background
There was a user report of pipeline failures when both
ImageFileName
andCommandLine
were populated.The table of existing test data below suggests that
ImageFileName
values will better match the ECS fieldprocess.executable
, which is described as "Absolute path to the process executable".ImageFileName
CommandLine
/bin/sh
/bin/sh -s unix:cmd
/usr/libexec/xpcproxy
xpcproxy com.apple.mdworker.shared.01000000-0600-0000-0000-000000000000
/usr/bin/pgbackrest
pgbackrest --stanza\u003dmain archive-get 000000020004D51F0000009F pg_wal/RECOVERYXLOG
/bin/uname
uname -a
\Device\HarddiskVolume2\projects\splunk-forwarder\bin\splunk-powershell.exe
D:\projects\splunk-forwarder\bin\splunk-powershell.exe --ps2
/usr/bin/plutil
/usr/bin/plutil -convert xml1 -o - /Applications/Xcode.app/Contents/Developer/Platforms/AppleTVOS.platform/Developer/Library/CoreSimulator/Profiles/Runtimes/tvOS.simruntime/Contents/Resources/RuntimeRoot/System/Library/PrivateFrameworks/DiagnosticExtensions.framework/PlugIns/com.apple.DiagnosticExtensions.CrashLogs.appex/Info.plist
\Device\HarddiskVolume3\Windows\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
\Device\HarddiskVolume3\Windows\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s NetSetupSvc
\Device\HarddiskVolume3\Windows\System32\backgroundTaskHost.exe
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXnme9zjyebb2xnyygh6q9ev6p5d234br2.mca
Checklist
changelog.yml
file.Related issues
process.executable
#8325