LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Sysmon events carry both a ProcessId and a ProcessGuid. Why is the GUID needed?

Because Windows reuses process IDs: the same PID can belong to a different process an hour later, while the ProcessGuid is unique for one process instance, so it links events reliably.

Timeline: chrome.exe and later evil.exe both get PID 4812; a network event joined on PID alone blames chrome, joined on GUID finds evil.exe

* PIDs are recycled; the ProcessGuid names one process instance. *

A PID is just a small number Windows hands out and recycles as soon as a process ends. If an analyst joins "network connection from PID 4812" with "process created with PID 4812", the two events may belong to entirely different programs that happened to receive the same number at different times.

Sysmon therefore derives a ProcessGuid from the machine GUID, the process start time and the process token ID. It is stable for exactly one process lifetime. Every event about that process (its creation, its network connections, its file writes, its termination) carries the same GUID, and child processes carry it as ParentProcessGuid. In Splunk or Kibana, joining on the GUID reconstructs a process tree without false links. LogonGuid does the same for logon sessions.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026