Files
splunk-security_content/macros/ms_defender.yml
2023-12-06 18:40:13 +00:00

5 lines
265 B
YAML

definition: source="WinEventLog:Microsoft-Windows-Windows Defender/Operational"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: ms_defender