Splunk SPL查询:如何获取指定进程的祖父进程ID?
SPL查询祖父进程ID实现方案
问题原因
你当前的查询直接调用grand_parent_id字段无法返回结果,是因为原始日志中没有预先存储该字段,需要通过父进程ID关联全量进程数据查询得到。
可用查询语句
index=data process=calc.exe | fields process_id parent_process_id # 重命名父进程ID为关联键,用于匹配全量进程数据中的进程ID | rename parent_process_id as target_pid # 左关联全量进程数据,获取父进程对应的父进程ID即祖父进程ID | join type=left target_pid [ search index=data | fields process_id parent_process_id | rename process_id as target_pid, parent_process_id as grand_parent_id ] # 输出最终需要的三个字段 | table process_id parent_process_id grand_parent_id
可选优化
- 如果需要排除祖父进程ID为空的无效结果,可以在
table命令前添加| where isnotnull(grand_parent_id) - 如果你的日志中进程ID、父进程ID的字段名和示例不一致,替换为你实际使用的字段名即可
内容的提问来源于stack exchange,提问作者ZG9udC1kZWxldGUtbWU
相关产品推荐
相关产品推荐

