updating macro

This commit is contained in:
research-bot
2025-01-07 12:15:23 -08:00
parent c4d5915f22
commit e66bb09cf4
+1 -1
View File
@@ -1,4 +1,4 @@
definition: ( source="WinEventLog:Microsoft-Windows-Windows Defender/Operational" OR source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"
definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational" OR source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environment.
name: ms_defender