osquery-1/osquery/tables/specs/x/processes.table
2015-02-06 19:05:50 -08:00

22 lines
716 B
Plaintext

table_name("processes")
description("All running processes on the host system.")
schema([
Column("pid", INTEGER),
Column("name", TEXT, "The process path or shorthand argv[0]"),
Column("path", TEXT),
Column("cmdline", TEXT, "Complete argv"),
Column("uid", BIGINT),
Column("gid", BIGINT),
Column("euid", BIGINT),
Column("egid", BIGINT),
Column("on_disk", TEXT, "The process path exist yes=1, no=-1"),
Column("wired_size", TEXT),
Column("resident_size", TEXT),
Column("phys_footprint", TEXT),
Column("user_time", TEXT),
Column("system_time", TEXT),
Column("start_time", TEXT),
Column("parent", INTEGER),
])
implementation("system/processes@genProcesses")