Files
splunk-security_content/macros/windows_shells.yml
T
2021-12-13 14:37:40 -07:00

5 lines
273 B
YAML

definition: (Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe)
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: windows_shells