config: add PrintService Operational
This commit is contained in:
@@ -52,6 +52,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
EventLog: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
EventLog: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -52,6 +52,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
log_name: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
log_name: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -52,6 +52,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
log_name: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
log_name: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -76,6 +76,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
channel: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
channel: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
index: windows
|
||||
|
||||
@@ -52,6 +52,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
event_source: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
event_source: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -73,6 +73,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
Channel: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
Channel: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -79,6 +79,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -93,6 +93,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
LogName: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -89,6 +89,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
source: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
source: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -76,6 +76,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
EventChannel: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
EventChannel: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -200,7 +200,12 @@ logsources:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
sources:
|
||||
- "Microsoft-Windows-SmbClient/Security"
|
||||
- "WinEventLog:Microsoft-Windows-SmbClient/Security"
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
sources:
|
||||
- "WinEventLog:Microsoft-Windows-PrintService/Operational"
|
||||
windows-applocker:
|
||||
product: windows
|
||||
service: applocker
|
||||
|
||||
@@ -60,6 +60,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
@@ -59,6 +59,11 @@ logsources:
|
||||
service: printservice-admin
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-PrintService/Admin'
|
||||
windows-printservice-operational:
|
||||
product: windows
|
||||
service: printservice-operational
|
||||
conditions:
|
||||
winlog.channel: 'Microsoft-Windows-PrintService/Operational'
|
||||
windows-smbclient-security:
|
||||
product: windows
|
||||
service: smbclient-security
|
||||
|
||||
Reference in New Issue
Block a user