<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: process_name log field in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205058#M8158</link>
    <description>&lt;P&gt;this query is works of course, but i cannot see how it is related to my issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2024 13:47:42 GMT</pubDate>
    <dc:creator>gm446</dc:creator>
    <dc:date>2024-02-05T13:47:42Z</dc:date>
    <item>
      <title>process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205037#M8155</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;As part of implementing SIEM solution in our organization i got a request from the CISO to log from the endpoint what process generates traffic.&lt;BR /&gt;i can see in &lt;A title="sk144192" href="https://support.checkpoint.com/results/sk/sk144192" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk144192&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/A&gt;that there is a "process_name" field under "&lt;STRONG&gt;Harmony Endpoint - Common Fields&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;unfortunately, i cannot find this field in actual logs for firewall, TP, Anti-Malware or Anti-Bot blades. is there anything specific i should enable for the client to log this information?&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Yossi.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 10:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205037#M8155</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-02-05T10:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205045#M8156</link>
      <description>&lt;P&gt;Hey Yossi,&lt;/P&gt;
&lt;P&gt;Let me check this in the lab later.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 12:07:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205045#M8156</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T12:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205055#M8157</link>
      <description>&lt;P&gt;Sorry, just working on some Azure stuff now, but have you tried below query to see if it yields anything?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;blade:"Endpoint Compliance"&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205055#M8157</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T13:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205058#M8158</link>
      <description>&lt;P&gt;this query is works of course, but i cannot see how it is related to my issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:47:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205058#M8158</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-02-05T13:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205059#M8159</link>
      <description>&lt;P&gt;No no, I get that, I was just curious if it worked or not. I will check again in a bit, but you may want to open the support case in the meantime to confirm.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:52:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205059#M8159</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T13:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205093#M8160</link>
      <description>&lt;P&gt;process_name refers to the (potentially) malicious process that is being blocked, not the blade that blocked it.&lt;BR /&gt;Based on this SK, it would seem we don't log which blade is responsible for the block, though it can be inferred from the other fields included.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 21:25:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205093#M8160</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-05T21:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205121#M8163</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;this is exactly the information i need, the process who is made the traffic and being blocked/allow.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Yossi.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 07:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205121#M8163</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-02-06T07:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205143#M8165</link>
      <description>&lt;P&gt;Did you end up opening TAC case to see if you can verify that info, if its possible?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:04:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205143#M8165</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T12:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205214#M8170</link>
      <description>&lt;P&gt;The only place it would show...when it is relevant...is in the full log card.&lt;BR /&gt;In any case, you may need to consult with TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 19:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205214#M8170</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-06T19:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205290#M8178</link>
      <description>&lt;P&gt;Thank you all, i opened a ticket and wait for an answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 11:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205290#M8178</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-02-07T11:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205297#M8180</link>
      <description>&lt;P&gt;Let us know what they say.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 12:22:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/205297#M8180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-07T12:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: process_name log field</title>
      <link>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/210336#M8469</link>
      <description>&lt;P&gt;After TAC investigation my request is not possible. so we achieve this logs through Sysmon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 10:51:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/process-name-log-field/m-p/210336#M8469</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2024-04-03T10:51:30Z</dc:date>
    </item>
  </channel>
</rss>

