Fix WEF inputs for Splunk

This commit is contained in:
Chris Long
2019-04-28 13:12:53 -07:00
parent 12c1ca677e
commit 3de47b621a
2 changed files with 31 additions and 3 deletions

View File

@@ -384,6 +384,33 @@ start_from = oldest
current_only = 0
checkpointInterval = 5
[WinEventLog://WEC7-Active-Directory]
sourcetype = WinEventLog:Security
source = WinEventLog:Active-Directory
index=wineventlog
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
[WinEventLog://WEC7-Terminal-Services]
sourcetype = WinEventLog:Security
source = WinEventLog:Terminal-Services
index=wineventlog
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
[WinEventLog://WEC7-Privilege-Use]
sourcetype = WinEventLog:Security
source = WinEventLog:Privilege-Use
index=wineventlog
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
[monitor://c:\pslogs]
index = powershell
sourcetype = powershell_transcript