mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating sysmon macro
This commit is contained in:
+1
-1
@@ -1,4 +1,4 @@
|
||||
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
definition: sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR source=Syslog:Linux-Sysmon/Operational
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
name: sysmon
|
||||
|
||||
Reference in New Issue
Block a user