# Winlogbeat NewProcessFields Function Missing Parent Process

**URL:** <https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679>\
**Category:** Beats\
**Tags:** beats-module, winlogbeat\
**Created:** [November 19, 2021, 11:25am UTC](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679 "2021-11-19T11:25:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [November 19, 2021, 11:25am UTC](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679/1 "2021-11-19T11:25:35Z")

</div>

Hi Elastic Team,

I'm writing to request an update to the winlogbeat [Windows Security module](https://github.com/elastic/beats/blob/master/x-pack/winlogbeat/module/security/config/winlogbeat-security.js) to add the parent process ID value for Windows Security event 4688.

Lines 2132 to 2142 handle field renames for parent/child process fields in 4688:

```auto
    var renameNewProcessFields = new processor.Chain()
        .Convert({
            fields: [
                {from: "winlog.event_data.NewProcessId", to: "process.pid", type: "long"},
                {from: "winlog.event_data.NewProcessName", to: "process.executable"},
                {from: "winlog.event_data.ParentProcessName", to: "process.parent.executable"}
            ],
            mode: "rename",
            ignore_missing: true,
            fail_on_error: false,
        })

```

The parent process ID is missing from the function, which affects Windows Security Event 4688. Looking at a raw sample for a 4688, the parent process in **friendly view** is re-labeled by Microsoft as _Creator Process ID_. However, the XML shows the parent process ID structured as _ProcessId_:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/8/983f7e17bb33e51790db6c84dbe4b4c52f1501f3.png)

The winlogbeat security module variable _event4688_ references the _renameNewProcessFields_ function and is the only variable that does, so I propose the _renameNewProcessFields_ function be updated to include the parent process PID:

```auto
    var renameNewProcessFields = new processor.Chain()
        .Convert({
            fields: [
                {from: "winlog.event_data.NewProcessId", to: "process.pid", type: "long"},
                {from: "winlog.event_data.NewProcessName", to: "process.executable"},
                {from: "winlog.event_data.ParentProcessName", to: "process.parent.executable"}
                {from: "winlog.event_data.ProcessId", to: "process.parent.pid"} //<---updated line
            ],
            mode: "rename",
            ignore_missing: true,
            fail_on_error: false,
        })

```

Since it's an event-dependent variable reference, the context will only be invoked for 4688s and not conflict with any others.

Please advise if this can be submitted via Github as well, or how the request process flows from the discussion area.

Thank you!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 19, 2021, 3:12pm UTC](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679/2 "2021-11-19T15:12:14Z")

</div>

Thanks for the detailed report. Yes, please open a Github issue for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2021, 5:12pm UTC](https://discuss.elastic.co/t/winlogbeat-newprocessfields-function-missing-parent-process/289679/3 "2021-12-17T17:12:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
