# Process telemetry returned from procs.go in Packetbeat github

**URL:** <https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349>\
**Category:** Beats\
**Tags:** elastic-stack-security, packetbeat\
**Created:** [March 5, 2020, 5:25pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349 "2020-03-05T17:25:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jostromsttora](https://avatars.discourse-cdn.com/v4/letter/j/74df32/32.png) [@jostromsttora](https://discuss.elastic.co/u/jostromsttora)\
**Post date:** [March 5, 2020, 5:25pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349/1 "2020-03-05T17:25:46Z")

</div>

Hi, I noticed in Packetbeats github repo from two days ago, a commit for procs.go that includes returning process telemetry. I've configured my packetsbeat v7.6.1 to send logs and visualized in Kibana. However, I don't see the PID / executable, command line arguments telemetry. Very interested in this for security use cases. Can anyone help direct me? Do I need a special config.yml? Processors?

Here are the lines of returned process information in procs.go, line 326:  
"  
return &process{  
pid: info.PID,  
ppid: info.PPID,  
name: name,  
exe: info.Exe,  
cwd: info.CWD,  
args: info.Args,  
startTime: info.StartTime,  
expiration: time.Now().Add(processCacheExpiration),  
}  
"  
URL: [https://github.com/elastic/beats/blob/master/packetbeat/procs/procs.go#L326-L334](https://github.com/elastic/beats/blob/master/packetbeat/procs/procs.go#L326-L334)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 16, 2020, 10:25pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349/2 "2020-03-16T22:25:10Z")

</div>

Checkout the documentation for Packetbeat regarding process enrichment: [https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-processes.html](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-processes.html). You need to enable it in the config file.

---

<div class="post-metadata">

**Author:** ![jostromsttora](https://avatars.discourse-cdn.com/v4/letter/j/74df32/32.png) [@jostromsttora](https://discuss.elastic.co/u/jostromsttora)\
**Post date:** [March 17, 2020, 12:14pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349/3 "2020-03-17T12:14:23Z")

</div>

Excellent. Thank you for the response. I turned this on and the process enrichment looks very good. This is a great feature and I really appreciate it once again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2020, 12:14pm UTC](https://discuss.elastic.co/t/process-telemetry-returned-from-procs-go-in-packetbeat-github/222349/4 "2020-04-14T12:14:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
