You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk SPL查询:如何获取指定进程的祖父进程ID?

SPL查询祖父进程ID实现方案

问题原因

你当前的查询直接调用grand_parent_id字段无法返回结果,是因为原始日志中没有预先存储该字段,需要通过父进程ID关联全量进程数据查询得到。

可用查询语句

index=data process=calc.exe
| fields process_id parent_process_id
# 重命名父进程ID为关联键,用于匹配全量进程数据中的进程ID
| rename parent_process_id as target_pid
# 左关联全量进程数据,获取父进程对应的父进程ID即祖父进程ID
| join type=left target_pid [
    search index=data
    | fields process_id parent_process_id
    | rename process_id as target_pid, parent_process_id as grand_parent_id
  ]
# 输出最终需要的三个字段
| table process_id parent_process_id grand_parent_id

可选优化

  • 如果需要排除祖父进程ID为空的无效结果,可以在table命令前添加 | where isnotnull(grand_parent_id)
  • 如果你的日志中进程ID、父进程ID的字段名和示例不一致,替换为你实际使用的字段名即可

内容的提问来源于stack exchange,提问作者ZG9udC1kZWxldGUtbWU

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 05:36:03