Filter Uncommon Host Processes


Read here (Uncommon Processes) that the Uncommon Processes query is an aggregation on sorted by host cardinality first (cardinality of where this process name occurs) and number of documents second.

The result is that the list if full of processes from our Rundeck server, which generates a unique id for each job running.

Is there any way to prevent these processes from showing up in SIEM? They look like:




I'm assuming there is no way to exclude processes somehow in hte SIEM Host overview?

Sorry for missing to reply. No, there's no way to add some sort of global filter at the moment. It's something we would consider.

You can filter them out via the KQL bar, but that will be only for the current view.

I'll raise this with the team to see if we can think of a solution.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.