This job appears to be looking at a list of process create events to determine if a process is new or existed previously. The issue I think we are having is it is alerting us on a lot of processes that existed previously because the service/process has been running for an extended period of time (I.E. the server hasn't been restarted for a while).
I think to resolve this issue the timeframe the job compares the data with should be extended but I'm not sure how to adjust this.
So my question is:
- Is the model snapshot retention days (default to 10) basically saying it will compare the previous 10 days? I read the articles but having a difficult time understanding. In my case, if those processes aren't restarted every 10 days then it is going to alert about it being a "new" process when it actually isn't. I would like to expand it to 30 days if that is what that value is.