Added rewrite config to generic sysmon configuration
This commit is contained in:
@@ -4,3 +4,6 @@ logsources:
|
||||
product: windows
|
||||
conditions:
|
||||
EventID: 1
|
||||
rewrite:
|
||||
category: null
|
||||
service: sysmon
|
||||
|
||||
Reference in New Issue
Block a user