mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
16 lines
589 B
YAML
16 lines
589 B
YAML
name: Windows Event Log CAPI2
|
|
id: b77e7a42-6bde-4ff5-971f-5115a8747b66
|
|
author: Patrick Bareiss, Splunk
|
|
source: XmlWinEventLog:Microsoft-Windows-CAPI2/Operational
|
|
sourcetype: xmlwineventlog
|
|
separator: EventCode
|
|
supported_TA:
|
|
name: Splunk Add-on for Microsoft Windows
|
|
version: 8.8.0
|
|
url: https://splunkbase.splunk.com/app/742
|
|
event_names:
|
|
- event_name: Windows Event Log CAPI2 70
|
|
data_source: data_sources/endpoint/event_sources/Windows_Event_Log_CAPI2_70.yml
|
|
- event_name: Windows Event Log CAPI2 81
|
|
data_source: data_sources/endpoint/event_sources/Windows_Event_Log_CAPI2_81.yml
|