Sysmon 13.33: Parent Process GUID / Parent Process Image / Parent Process Command Line / Parent Process User in EID1 are empty after a while

Joe Doe 156 Reputation points
2022-03-04T09:52:47.97+00:00

Hi guys,
I've seen that after a while the fields Parent Process GUID / Parent Process Image / Parent Process Command Line / Parent Process User are empty for EventID 1. Did somebody has seen this too?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,088 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. 7'3 Big Dawg 0 Reputation points
    2023-11-01T18:31:18.2166667+00:00

    Hello,

    Has anyone identified the solution to this issue. I am experiencing the problem using v14.11. Does v15 have this issue? The only parent information of svchost.exe is the ParentProcessId which is services.exe. I didn't see this issue until I upgraded from v10. This is a strange issue.

    Thanks!

    0 comments No comments