Skip to content

Parse SRUM Application Usage

Evidence: Parse SRUM Application Usage
Description: Parse System Resource Usage Monitor (SRUM) Application Resource Usage data.
Category:
Platform: windows
Short Name: srumappparse
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers structured data about parse srum application usage.

FieldDescriptionExample
AutoIncIdAuto-increment ID from SRUM database123
TimestampTimestamp2023-10-15 14:30:25
ApplicationNameApplication NameExample Name
UserSidWindows SID in S-1-5-… format (from SRUM IdMapTable)S-1-5-21-…
UserNameResolved username via Windows API (LookupAccountSidW)Example Name
ForegroundCycleTimeForeground Cycle Time2023-10-15 14:30:25
BackgroundCycleTimeBackground Cycle Time2023-10-15 14:30:25
FacetimeFacetime2023-10-15 14:30:25
ForegroundContextSwitchesForeground Context Switches123
BackgroundContextSwitchesBackground Context Switches123
ForegroundBytesReadForeground Bytes Read1024
ForegroundBytesWrittenForeground Bytes Written1024
ForegroundNumReadOperationsForeground Num Read Operations123
ForegroundNumWriteOperationsForeground Num Write Operations123
ForegroundNumberOfFlushesForeground Number Of Flushes123
BackgroundBytesReadBackground Bytes Read1024
BackgroundBytesWrittenBackground Bytes Written1024
BackgroundNumReadOperationsBackground Num Read Operations123
BackgroundNumWriteOperationsBackground Num Write Operations123
BackgroundNumberOfFlushesBackground Number Of Flushes123