Added missing subscription forward rule

This commit is contained in:
Olaf Hartong
2020-04-30 21:53:05 +02:00
committed by GitHub
parent 6de7ffa8d5
commit 7476ff94df

View File

@@ -411,6 +411,15 @@ start_from = oldest
current_only = 0
checkpointInterval = 5
[WinEventLog://WEC2-Object-Manipulation]
sourcetype = WinEventLog:Security
source = WinEventLog:Object-Handle
index=wineventlog
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
[monitor://c:\pslogs]
index = powershell
sourcetype = powershell_transcript