Questions in the inputs.conf
[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = true
renderXml = 1
I see the default is to disable XML however there are vague references to XM in the doc. I saw it source types it to XML in the next line.
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Are both types possible and is XML preferred or recommended? I was looking for some advice and didn't see any in the doc.
Thank you.