Add transforms to remove eventid description text
This commit is contained in:
@@ -1,5 +1,8 @@
|
|||||||
[source::WinEventLog:*]
|
[source::WinEventLog:*]
|
||||||
TRANSFORMS-host = wef_computername_as_host
|
TRANSFORMS-host = wef_computername_as_host
|
||||||
|
TRANSFORMS-removedescription1 = removeEventDesc1
|
||||||
|
TRANSFORMS-removedescription2 = removeEventDesc2
|
||||||
|
TRANSFORMS-null = autoruns_wineventlog_null
|
||||||
|
|
||||||
[powershell_transcript]
|
[powershell_transcript]
|
||||||
TRANSFORMS-powershell_rename_host = powershell_rename_host
|
TRANSFORMS-powershell_rename_host = powershell_rename_host
|
||||||
@@ -23,5 +26,3 @@ TRUNCATE = 0
|
|||||||
[osquery:status]
|
[osquery:status]
|
||||||
TRANSFORMS-null = osquery_status_filter
|
TRANSFORMS-null = osquery_status_filter
|
||||||
|
|
||||||
[WinEventLog]
|
|
||||||
TRANSFORMS-null = autoruns_wineventlog_null
|
|
||||||
|
|||||||
Reference in New Issue
Block a user