Add transforms to remove eventid description text
This commit is contained in:
@@ -1,5 +1,8 @@
|
||||
[source::WinEventLog:*]
|
||||
TRANSFORMS-host = wef_computername_as_host
|
||||
TRANSFORMS-removedescription1 = removeEventDesc1
|
||||
TRANSFORMS-removedescription2 = removeEventDesc2
|
||||
TRANSFORMS-null = autoruns_wineventlog_null
|
||||
|
||||
[powershell_transcript]
|
||||
TRANSFORMS-powershell_rename_host = powershell_rename_host
|
||||
@@ -23,5 +26,3 @@ TRUNCATE = 0
|
||||
[osquery:status]
|
||||
TRANSFORMS-null = osquery_status_filter
|
||||
|
||||
[WinEventLog]
|
||||
TRANSFORMS-null = autoruns_wineventlog_null
|
||||
|
||||
Reference in New Issue
Block a user