Fix sysmon sourcetype, update ThreatHunting app
This commit is contained in:
@@ -323,7 +323,7 @@ current_only = 0
|
||||
checkpointInterval = 5
|
||||
|
||||
[WinEventLog://WEC6-Sysmon]
|
||||
sourcetype = "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"
|
||||
sourcetype = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
source = WinEventLog:Sysmon
|
||||
index=sysmon
|
||||
disabled = 0
|
||||
|
||||
Binary file not shown.
BIN
Vagrant/resources/splunk_server/threathunting_144.tgz
Normal file
BIN
Vagrant/resources/splunk_server/threathunting_144.tgz
Normal file
Binary file not shown.
Reference in New Issue
Block a user