Hello CJ Jung
Welcome to Microsoft Q&A Platform, thanks for posting your query here.
In Linux, syslog does not include PID information by default.
You have to use a custom log to collect PID and PPID information.
Hope that helps.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi
I wonder why syslog collected in Linux does not have PID information.
Is there any way to collect PID and PPID information from Linux?
For example, in Windows, SecurityEvent log include information about PID (i.e., which command is executed), so that users can trace back which process is called by which process.
Maybe it can be possible by configuring something, but I don't see this in Linux.
Anyone can give me a help?
Is creating custom log only way to do this?
Hello CJ Jung
Welcome to Microsoft Q&A Platform, thanks for posting your query here.
In Linux, syslog does not include PID information by default.
You have to use a custom log to collect PID and PPID information.
Hope that helps.
@CJ Jung, Thanks for posting in Q&A. From your description, I know the issue is with Linux which we are not familiar. Then I go to do some research, But I don't find the method to include PID and PPID into syslog. In fact, a process will likely have a different PID every time you launch it. As a workaround, you can run commands to get the PID and PPID when we see the log generated. Here is a link with the commands to get PID and PPID:
Note: Non-Microsoft link, just for the reference.
You can also contact your Linux OS supporting to see if they can help on this.
Thanks for your understanding.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.