mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
bd69016d7e
Modified macro to capture both XML rendered and non. Issue is, if you renderXML for powershell logging, it will have different fields. Something to be aware of.
5 lines
325 B
YAML
5 lines
325 B
YAML
definition: (source=WinEventLog:Microsoft-Windows-PowerShell/Operational OR source="XmlWinEventLog:Microsoft-Windows-PowerShell/Operational")
|
|
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
|
Replace the macro definition with configurations for your Splunk Environmnent.
|
|
name: powershell
|