Process search or alert shows a process of "(unknown)"
Common causes for (unknown) processes:
While it unknowns may still exist if the OS does not return enough information from the child to add the info, the recommendation is to upgrade the server and sensor to the latest versions.
If this is triggering many alerts, adding the search parameter of process_name:* and/or parent_name:* to your query will only return results with names. Doing this will not introduce performance issues into the query as these fields are indexed.