Since some network administrators may rely on our log format, another minor change has occured. The format remains the same, no worries. On process creation events, the command line is used if arg0 (pathname) is present. If not, the pathname is prepended to the command line and used. So, count on a 'proper' full command line being in the description column. This was necessary as the presence of arg0 isn't mandatory, and so will vary depending on the parameters used when CreateProcess is invoked (iow, depending on how the process was launched).
This starts as of v3.99.40, coming soon.
0 comments:
Post a Comment