Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add PIDs by default #2209

Closed
spyder-kyle opened this issue Sep 14, 2022 · 1 comment · Fixed by #2211
Closed

Add PIDs by default #2209

spyder-kyle opened this issue Sep 14, 2022 · 1 comment · Fixed by #2211

Comments

@spyder-kyle
Copy link
Contributor

Motivation

The default rules lack a unique identifier for the processes that cause events, making it impossible to merge information with other sources in many cases.

Feature

Adding pid=%proc.pid to the output of all the default rules would be perfect. I could easily create a PR for this if necessary.

Alternatives

One could override all the rules and specify PIDs, or append to all their outputs if that functionality is added, but the number of default rules makes either option not appealing.

Additional context

@jasondellaluce
Copy link
Contributor

@spyder-kyle I would suggest opening a PR with the proposed changes and move the discussion there

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants