mirror of https://github.com/MISP/misp-objects
chg: [process] revert back to single char in light of the new process-attribute
parent
eaf0301fe3
commit
e67b937f73
|
@ -44,23 +44,23 @@
|
||||||
"process-state": {
|
"process-state": {
|
||||||
"description": "State of process.",
|
"description": "State of process.",
|
||||||
"sane_default": [
|
"sane_default": [
|
||||||
"D uninterruptible sleep (usually IO)",
|
"D",
|
||||||
"R running or runnable (on run queue)",
|
"R",
|
||||||
"S interruptible sleep (waiting for an event to complete)",
|
"S",
|
||||||
"T stopped by job control signal",
|
"T",
|
||||||
"t stopped by debugger during the tracing",
|
"t",
|
||||||
"W paging (not valid since the 2.6.xx kernel)",
|
"W",
|
||||||
"X dead (should never be seen)",
|
"X",
|
||||||
"Z defunct ('zombie') process, terminated but not reaped by its parent",
|
"Z",
|
||||||
"< high-priority (not nice to other users)",
|
"<",
|
||||||
"N low-priority (nice to other users)",
|
"N",
|
||||||
"L has pages locked into memory (for real-time and custom IO)",
|
"L",
|
||||||
"s is a session leader",
|
"s",
|
||||||
"l is multi-threaded (using CLONE_THREAD, like NPTL pthreads do)",
|
"l",
|
||||||
"+ is in the foreground process group"
|
"+"
|
||||||
],
|
],
|
||||||
"ui-priority": 1,
|
"ui-priority": 1,
|
||||||
"misp-attribute": "text",
|
"misp-attribute": "process-state",
|
||||||
"multiple": false,
|
"multiple": false,
|
||||||
"disable_correlation": true
|
"disable_correlation": true
|
||||||
},
|
},
|
||||||
|
|
Loading…
Reference in New Issue