You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
8 lines
557 B
8 lines
557 B
[WinEventLog://Microsoft-Windows-Sysmon/Operational]
|
|
disabled = true
|
|
renderXml = 1
|
|
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
# Prevent forwarding of multiple DNSQuery logs based on complex rule groups
|
|
# blacklist1 = EventCode="^22$" Message="(?i)QueryName:\s+(.*\.arpa\.)\s+QueryStatus:\s+(\d+)\s+QueryResults:\s+(.*)\s+Image:\s+(c:\\windows\\sysmon\.exe)$"
|
|
# blacklist2 = EventCode="^22$" Message="(?i)QueryName:\s+(HelloWorld.local)\s+QueryStatus:\s+(\d+)\s+QueryResults:\s+(.*)\s+Image:\s+(c:\\windows\\system32\\ping\.exe)$”
|