# Adapting ECS process field set for a process tree?

**URL:** <https://discuss.elastic.co/t/adapting-ecs-process-field-set-for-a-process-tree/289374>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [November 17, 2021, 12:04am UTC](https://discuss.elastic.co/t/adapting-ecs-process-field-set-for-a-process-tree/289374 "2021-11-17T00:04:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gerry7](https://avatars.discourse-cdn.com/v4/letter/g/f17d59/32.png) [@Gerry7](https://discuss.elastic.co/u/Gerry7)\
**Post date:** [November 17, 2021, 12:04am UTC](https://discuss.elastic.co/t/adapting-ecs-process-field-set-for-a-process-tree/289374/1 "2021-11-17T00:04:17Z")

</div>

We have a system sending alerts on process activity. The alert contains an entire process tree related to the offending process - the parent process, grand parent proces, etc.

The ECS process field set has a parent node, _process.parent_, under which process fields can be nested. Does parent nesting allow for multiple generations of parents, e.g. _process.parent.parent_ and _process.parent.parent.parent_?

The alert that my system generates looks something like this

```auto
{
    "alert_id": 1234,
    "alert_type" : "unexpected process",
    "properties": {
        "args": "\"D:\\program1.exe\" ",
        "pid": 1788,
        "ppid": 6832,
        "start_time": "2021-05-17T13:10:39Z",
        "user": "NT AUTHORITY\\SYSTEM",
        "parent": {
            "args": "\"D:\\program2.exe\"",
            "pid": 6832,
            "ppid": 744,
            "start_time": "2021-05-17T04:20:56Z",
            "user": "NT AUTHORITY\\SYSTEM",
            "parent": {
                "args": "C:\\WINDOWS\\system32\\services.exe",
                "pid": 744,
                "ppid": 604,
                "start_time": "2021-05-17T04:20:06Z",
                "user": "NT AUTHORITY\\SYSTEM"
            }
        }
    }
}

```

Could this be mapped to an ECS event that includes the entire process tree like below?

```auto
{
    "event" : {
        "id" : 1234,
        "dataset" :"systemx",
        "kind" : "alert",
        "reason" : "unexpected process"
    },
    "process" : {
        "args": "\"D:\\program1.exe\" ",
        "name": "program1.exe",
        "pid": 1788,
        "ppid": 6832,
        "start": "2021-05-17T13:10:39Z",
        "parent": {
            "args": "\"D:\\program2.exe\"",
            "name": "program2.exe",
            "pid": 6832,
            "ppid": 744,
            "start": "2021-05-17T04:20:56Z",
            "parent": {
                "args": "C:\\WINDOWS\\system32\\services.exe",
                "name" : "services.exe",
                "pid": 744,
                "ppid": 604,
                "start": "2021-05-17T04:20:06Z",
            }
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![kgeller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kgeller/32/85639_2.png) [@kgeller](https://discuss.elastic.co/u/kgeller)\
**Post date:** [November 17, 2021, 3:15pm UTC](https://discuss.elastic.co/t/adapting-ecs-process-field-set-for-a-process-tree/289374/2 "2021-11-17T15:15:06Z")

</div>

Hi @Gerry7 !

Great question. Unfortunately `process.*` is only nested as `process.parent.*` once in ECS. If you want to be able to have a 'grandparent' process, you'd need to create a custom field. The [ecs docs](https://www.elastic.co/guide/en/ecs/master/ecs-custom-fields-in-ecs.html#ecs-custom-fields-in-ecs) have some good information about our recommendations for custom fields, such as capitalization (so you'd have `process.parent.Parent`).

Not quite related to your ask, but in the security app analyzer, we do stitch together process trees from multiple events. See [here](https://www.elastic.co/guide/en/security/current/visual-event-analyzer.html#visual-analyzer-ui) for the docs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2021, 3:15pm UTC](https://discuss.elastic.co/t/adapting-ecs-process-field-set-for-a-process-tree/289374/3 "2021-12-15T15:15:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
