Files
splunk-security_content/macros/is_windows_system_file.yml
2020-02-04 09:15:39 -08:00

6 lines
255 B
YAML

definition: lookup update=true is_windows_system_file filename as process_name
OUTPUT systemFile | search systemFile=true
description: This macro limits the output to process names that are in the Windows
System directory
name: is_windows_system_file