mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating macro
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
definition: ( source="WinEventLog:Microsoft-Windows-Windows Defender/Operational" OR source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"
|
||||
definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational" OR source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environment.
|
||||
name: ms_defender
|
||||
|
||||
Reference in New Issue
Block a user