# Uncommon Processes

**URL:** <https://discuss.elastic.co/t/uncommon-processes/190115>\
**Category:** SIEM\
**Created:** [July 11, 2019, 10:02pm UTC](https://discuss.elastic.co/t/uncommon-processes/190115 "2019-07-11T22:02:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [July 11, 2019, 10:02pm UTC](https://discuss.elastic.co/t/uncommon-processes/190115/1 "2019-07-11T22:02:06Z")

</div>

How does SIEM determine what is and is not an uncommon process?

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [July 15, 2019, 7:55am UTC](https://discuss.elastic.co/t/uncommon-processes/190115/2 "2019-07-15T07:55:06Z")

</div>

Hi @wwalker, the idea is to surface the processes that have occurred _on the least amount of hosts the least amount of times_. So if a process with that name has executed on just one out of all hosts just once, that would be displayed as the most "unusual" one.

The query for this is an aggregation on `process.name` sorted by host cardinality first (cardinality of `host.name` where this process name occurs) and number of documents second.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 12, 2019, 7:55am UTC](https://discuss.elastic.co/t/uncommon-processes/190115/3 "2019-08-12T07:55:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
