Activity Feed
- Got Karma for Re: How to properly map windows Endpoint DataModel with Windows logs?. 09-04-2023 12:07 AM
- Posted Re: How to properly map windows Endpoint DataModel with Windows logs? on Splunk Enterprise Security. 05-23-2021 07:33 PM
Topics I've Started
No posts to display.
05-23-2021
07:33 PM
1 Karma
Windows Event 4688 + tick the Command Line logging wineventlog : EVAL-parent_process_id parent_process_id Creator_Process_ID wineventlog : EVAL-parent_process_name parent_process_name case(EventCode=="4688", replace(Creator_Process_Name,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)","")) wineventlog : EVAL-parent_process_path parent_process_path Creator_Process_Name wineventlog : EVAL-process_command_line process_command_line Process_Command_Line wineventlog : EVAL-process_id process_id New_Process_ID wineventlog : EVAL-process_name process_name case(EventCode=="4688",replace(New_Process_Name,"(.*\\\)(?=.*(\.\w*)$|(\w+)$)",""),1==1,"") wineventlog : EVAL-process_path process_path case(EventCode=="4688",New_Process_Name)
... View more