osquery-1/specs/processes.table

29 lines
1.3 KiB
Plaintext
Raw Normal View History

table_name("processes")
description("All running processes on the host system.")
schema([
Column("pid", INTEGER, "Process (or thread) ID", index=True),
Column("name", TEXT, "The process path or shorthand argv[0]"),
2015-02-13 02:05:10 +00:00
Column("path", TEXT, "Path to executed binary"),
Column("cmdline", TEXT, "Complete argv"),
2015-02-13 02:05:10 +00:00
Column("cwd", TEXT, "Process current working directory"),
Column("root", TEXT, "Process virtual root directory"),
Column("uid", BIGINT, "Unsigned user ID"),
Column("gid", BIGINT, "Unsgiend groud ID"),
Column("euid", BIGINT, "Unsigned effective user ID"),
Column("egid", BIGINT, "Unsigned effective group ID"),
Column("on_disk", INTEGER,
"The process path exists yes=1, no=0, unknown=-1"),
Column("wired_size", BIGINT, "Bytes of unpagable memory used by process"),
Column("resident_size", BIGINT, "Bytes of private memory used by process"),
Column("phys_footprint", BIGINT, "Bytes of total physical memory used"),
Column("user_time", BIGINT, "CPU time spent in user space"),
Column("system_time", BIGINT, "CPU time spent in kernel space"),
Column("start_time", BIGINT,
"Process start in seconds since boot (non-sleeping)"),
2015-02-13 02:05:10 +00:00
Column("parent", INTEGER, "Process parent's PID"),
])
implementation("system/processes@genProcesses")
examples([
"select * from processes where pid = 1",
])