mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-15 14:57:23 +00:00
Merge branch 'atp-rs4' of https://cpubwin.visualstudio.com/_git/it-client into atp-rs4
This commit is contained in:
commit
b1087beacb
@ -39,8 +39,8 @@ The following best practices serve as a guideline of query performance best prac
|
|||||||
## Query tips and pitfalls
|
## Query tips and pitfalls
|
||||||
|
|
||||||
### Unique Process IDs
|
### Unique Process IDs
|
||||||
Process IDs are recycled in Windows and reused for new processes, so cannot serve as unique IDs for a specific process.
|
Process IDs are recycled in Windows and reused for new processes, so cannot serve as a unique identifier for a specific process.
|
||||||
To address this issue, the time the process was created for the Windows Defender ATP data. Together with the process ID, this can serve as a unique ID on a specific machine.
|
To address this issue, the time the process was created is part of the Windows Defender ATP data. Together with the process ID, this can serve as a unique ID on a specific machine.
|
||||||
|
|
||||||
So, when you join data based on a specific process or summarize data for each process, you'll need to use a machine identifier (either MachineId or ComputerName), a process ID (ProcessId or InitiatingProcessId) and the process creation time (ProcessCreationTime or InitiatingProcessCreationTime)
|
So, when you join data based on a specific process or summarize data for each process, you'll need to use a machine identifier (either MachineId or ComputerName), a process ID (ProcessId or InitiatingProcessId) and the process creation time (ProcessCreationTime or InitiatingProcessCreationTime)
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user