Merge pull request #434 from olafhartong/patch-1

Added missing subscription forward rule
This commit is contained in:
Chris Long
2020-05-02 12:17:39 -07:00
committed by GitHub

View File

@@ -411,6 +411,15 @@ start_from = oldest
current_only = 0
checkpointInterval = 5
[WinEventLog://WEC2-Object-Manipulation]
sourcetype = WinEventLog:Security
source = WinEventLog:Object-Handle
index=wineventlog
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
[monitor://c:\pslogs]
index = powershell
sourcetype = powershell_transcript