Files
splunk-security_content/macros/previously_seen_windows_services_forget_window.yml

9 lines
308 B
YAML

name: previously_seen_windows_services_forget_window
id: 26bf5f8f-2e77-4047-8a26-9af5c2fb7392
version: 1
creation_date: '2020-05-28'
modification_date: '2026-05-13'
author: Splunk Threat Research Team
description: Use this macro to determine how long to keep track of Windows services
definition: '"-90d@d"'