VQL Reference Frequently Used process_tracker_get process_tracker_get Function Arg Description Type id Process ID. string (required) max_items The maximum number of process entries to return (default 10) int64 Description Get a single process from the global tracker.