master
admingit 2 years ago
parent 4fd8e8e434
commit 9ab7639020

@ -11,28 +11,31 @@
###### OS Logs ###### ###### OS Logs ######
[WinEventLog://Application] [WinEventLog://Application]
disabled = 1 disabled = 0
start_from = oldest start_from = oldest
current_only = 0 current_only = 0
checkpointInterval = 5 checkpointInterval = 5
renderXml=true renderXml=true
index=wineventlog
[WinEventLog://Security] [WinEventLog://Security]
disabled = 1 disabled = 0
start_from = oldest start_from = oldest
current_only = 0 current_only = 0
evt_resolve_ad_obj = 1 evt_resolve_ad_obj = 1
checkpointInterval = 5 checkpointInterval = 5
blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)" blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)" blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"
renderXml=true renderXml=false
index=wineventlog
[WinEventLog://System] [WinEventLog://System]
disabled = 1 disabled = 0
start_from = oldest start_from = oldest
current_only = 0 current_only = 0
checkpointInterval = 5 checkpointInterval = 5
renderXml=true renderXml=true
index=wineventlog
###### Forwarded WinEventLogs (WEF) ###### ###### Forwarded WinEventLogs (WEF) ######
@ -214,13 +217,15 @@ disabled=1
###### Host monitoring ###### ###### Host monitoring ######
[WinHostMon://Computer] [WinHostMon://Computer]
interval = 600 interval = 600
disabled = 1 disabled = 0
type = Computer type = Computer
index = windows
[WinHostMon://Process] [WinHostMon://Process]
interval = 600 interval = 600
disabled = 1 disabled = 0
type = Process type = Process
index = windows
[WinHostMon://Processor] [WinHostMon://Processor]
interval = 600 interval = 600
@ -234,13 +239,15 @@ type = NetworkAdapter
[WinHostMon://Service] [WinHostMon://Service]
interval = 600 interval = 600
disabled = 1 disabled = 0
type = Service type = Service
index = windows
[WinHostMon://OperatingSystem] [WinHostMon://OperatingSystem]
interval = 600 interval = 600
disabled = 1 disabled = 0
type = OperatingSystem type = OperatingSystem
index = windows
[WinHostMon://Disk] [WinHostMon://Disk]
interval = 600 interval = 600
@ -254,8 +261,9 @@ type = Driver
[WinHostMon://Roles] [WinHostMon://Roles]
interval = 600 interval = 600
disabled = 1 disabled = 0
type = Roles type = Roles
index = windows
###### Print monitoring ###### ###### Print monitoring ######
[WinPrintMon://printer] [WinPrintMon://printer]
@ -439,4 +447,4 @@ script = ."$SplunkHome\etc\apps\Splunk_TA_windows\bin\powershell\windows_bios_da
schedule = 0 */24 * * * schedule = 0 */24 * * *
source = Powershell source = Powershell
sourcetype = win:bios sourcetype = win:bios
disabled = 1 disabled = 1
Loading…
Cancel
Save