Skip to content
Discussion options

You must be logged in to vote

No, this is an intentional error thrown by the CrowdStrike pipeline in case that ParentImage not only contains a file name (ParentImage|endswith: "\\parent.exe"), but more path components, e.g. ParentImage|endswith: "\\Windows\\System32\\something.exe". The reason is that CrowdStrike ProcessRollup2 events only contain the file name in the ParentBaseFileName field and therefore paths are not supported by its data model.

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
4 replies
@thekarannayak
Comment options

@thomaspatzke
Comment options

@thomaspatzke
Comment options

@thekarannayak
Comment options

Answer selected by thomaspatzke
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants