process.name is not currently exported by the CrowdStrike FDR. Based on a sample event where process.executable path that points to SoundVolumeView.exe, process.name should be set to SoundVolumeView.exe
Feedback from @leehinman: We will need to parse ImageFileName field from crowdstrike and split it on path separators, it will need to work for both Unix & Windows style paths.
process.name
is not currently exported by the CrowdStrike FDR. Based on a sample event where process.executable path that points to SoundVolumeView.exe,process.name
should be set toSoundVolumeView.exe
Feedback from @leehinman: We will need to parse ImageFileName field from crowdstrike and split it on path separators, it will need to work for both Unix & Windows style paths.