# Auditbeat System module: Add parent process entity\_id field to process and socket events

**URL:** <https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [March 29, 2019, 9:09pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610 "2019-03-29T21:09:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aaron\_Jewitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_jewitt/32/43128_2.png) [@Aaron\_Jewitt](https://discuss.elastic.co/u/Aaron_Jewitt)\
**Post date:** [March 29, 2019, 9:09pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/1 "2019-03-29T21:09:14Z")

</div>

Recommend adding the parent processes event\_id field to all System module process events as well as socket events.

Having the parent processes event\_id in a process and socket event would be extremely useful when conducting a forensic investigation using the System events. With this data it would be easy to create queries that quickly display all activity by a single process.

For example, in a windows domain with Sysmon I have built a kibana 'process investigation' dashboard for our SOC engineers where the engineer enters the Process Guid of the process under investigation to quickly see all activity from that processes. The dashboard is broken up into panels that display all child processes spawned, information about the parent process, all network connections, and any other events related to that process. I would like to create a similar dashboard for the Linux hosts in our domain that use the system module.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 1, 2019, 3:27pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/2 "2019-04-01T15:27:31Z")

</div>

We do have a [add\_process\_metadata](https://www.elastic.co/guide/en/beats/auditbeat/current/add-process-metadata.html) processor some users configure to enrich events with parent process information. Can you try doing that and seeing if it works for you?

```auto
processors:
- add_process_metadata:
    match_pids: [process.ppid]
    target: process.parent

```

---

<div class="post-metadata">

**Author:** ![olatunde.tokun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/olatunde.tokun/32/110546_2.png) [@olatunde.tokun](https://discuss.elastic.co/u/olatunde.tokun)\
**Post date:** [April 3, 2019, 8:02pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/3 "2019-04-03T20:02:32Z")

</div>

@andrewkroh don't believe this metadata works in the current versions on auditbeat6.7.

Auditbeat doesnt start when using it. Works in filebeat though.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 3, 2019, 8:14pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/4 "2019-04-03T20:14:51Z")

</div>

What error do you get and what's the config you're trying (`auditbeat export config`)?

---

<div class="post-metadata">

**Author:** ![olatunde.tokun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/olatunde.tokun/32/110546_2.png) [@olatunde.tokun](https://discuss.elastic.co/u/olatunde.tokun)\
**Post date:** [April 3, 2019, 8:31pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/5 "2019-04-03T20:31:17Z")

</div>

@andrewkroh, it does work now!

There was an error in processor indentation.

---

<div class="post-metadata">

**Author:** ![Aaron\_Jewitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_jewitt/32/43128_2.png) [@Aaron\_Jewitt](https://discuss.elastic.co/u/Aaron_Jewitt)\
**Post date:** [April 8, 2019, 1:30pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/6 "2019-04-08T13:30:37Z")

</div>

We made this modification to our config and I see the ppid value in the events, but not the entity\_id of the parent process. If this is successful as I was hoping for I should see two entity\_id fields in each process event, one for the process, and one for the parent process. Is that what I should be seeing or do I have an issue with my config?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 8, 2019, 2:27pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/7 "2019-04-08T14:27:34Z")

</div>

There's no issue on your end. The processor doesn't add the entity ID. The entity ID is new idea that was added into Auditbeat's system module, but the `add_process_metadata` processor hasn't been enhanced to support it (this is a generic processor that is shared by all Beats).

Would you mind opening an enhancement request in the Github repo for this feature? [https://github.com/elastic/beats/issues/new/choose](https://github.com/elastic/beats/issues/new/choose)

---

<div class="post-metadata">

**Author:** ![Aaron\_Jewitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_jewitt/32/43128_2.png) [@Aaron\_Jewitt](https://discuss.elastic.co/u/Aaron_Jewitt)\
**Post date:** [April 8, 2019, 3:33pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/8 "2019-04-08T15:33:44Z")

</div>

Opened as issue #11695

> <https://github.com/elastic/beats/issues/11695>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2019, 3:45pm UTC](https://discuss.elastic.co/t/auditbeat-system-module-add-parent-process-entity-id-field-to-process-and-socket-events/174610/9 "2019-04-29T15:45:47Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
