Files
splunk-security_content/data_sources/windows_event_log_security_4728.yml

20 lines
522 B
YAML

name: Windows Event Log Security 4728
id: c0cb4907-d715-41f2-a98a-4f4e75f248c1
version: 3
creation_date: '2025-02-21'
modification_date: '2026-05-13'
author: Bhavin Patel, Splunk
description: Data source object for Windows Event Log Security 4728
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
separator: EventCode
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
version: 10.0.1
fields:
- _time
output_fields:
- dest
example_log: ''