- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-28-2023 02:34 AM
Hello Everyone,
My intention is to fully understand the process tree naming convention for cortex XDR and the more I look at the logs the more confusing it becomes.
From my understanding the process tree from child to grandparent should look like below
11-30-2023 07:17 AM
Hi AvesterFahimipour,
The fields you are asking about shouldn't be thought about in terms of parent/child relationships, but instead, as their names suggest, actor and action. The actor is the process doing the action, and, obviously, the action is what is being performed. So if the agent is logging a process start, then yes, you will have action as the child and actor as the parent, however, if we are talking about another type of log, say, file activity, then the actor is the process and the action is the file activity.
Causality is the process that Cortex XDR has determined was responsible for originating the chain of events which led to the action being performed. The OS actor is the process identified by the operating system as the process that performed the action.
11-29-2023 06:25 AM
Hello again community,
After more research I believe that the action is always the child and the actor is always the parent.
And it seems that the OS and causality are the two that can be variables, but I still dont fully understand their behavior or what the OS and causality mean.
11-30-2023 07:17 AM
Hi AvesterFahimipour,
The fields you are asking about shouldn't be thought about in terms of parent/child relationships, but instead, as their names suggest, actor and action. The actor is the process doing the action, and, obviously, the action is what is being performed. So if the agent is logging a process start, then yes, you will have action as the child and actor as the parent, however, if we are talking about another type of log, say, file activity, then the actor is the process and the action is the file activity.
Causality is the process that Cortex XDR has determined was responsible for originating the chain of events which led to the action being performed. The OS actor is the process identified by the operating system as the process that performed the action.
12-01-2023 12:58 AM
Yah, I understood that about files but the causality and OS one was still vague to me.
What would be the cause of the actor and OS actor not being the same?
Thanks for the answer.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!