@fearful-symmetry released a systemd integration to find out if services are stopped, dead, running. https://github.com/elastic/beats/pull/14206 I think it would be nice if those show up in the SIEM app as an extra tab. Maybe it is possible to correlate the uncommon processes to the systemd services? E.g. is a process was spawned from systemd?
Describe the feature:
@fearful-symmetry released a systemd integration to find out if services are stopped, dead, running. https://github.com/elastic/beats/pull/14206 I think it would be nice if those show up in the SIEM app as an extra tab. Maybe it is possible to correlate the
uncommon processes
to the systemd services? E.g. is a process was spawned from systemd?