config: add PrintService Operational

This commit is contained in:
Florian Roth
2021-07-01 09:55:15 +02:00
parent 7a96b40895
commit 63f3fd7e73
13 changed files with 66 additions and 1 deletions
+5
View File
@@ -52,6 +52,11 @@ logsources:
service: printservice-admin
conditions:
EventLog: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
EventLog: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -52,6 +52,11 @@ logsources:
service: printservice-admin
conditions:
log_name: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
log_name: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -52,6 +52,11 @@ logsources:
service: printservice-admin
conditions:
log_name: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
log_name: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -76,6 +76,11 @@ logsources:
service: printservice-admin
conditions:
channel: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
channel: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
index: windows
+5
View File
@@ -52,6 +52,11 @@ logsources:
service: printservice-admin
conditions:
event_source: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
event_source: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -73,6 +73,11 @@ logsources:
service: printservice-admin
conditions:
Channel: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
Channel: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -79,6 +79,11 @@ logsources:
service: printservice-admin
conditions:
LogName: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
LogName: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -93,6 +93,11 @@ logsources:
service: printservice-admin
conditions:
LogName: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
LogName: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -89,6 +89,11 @@ logsources:
service: printservice-admin
conditions:
source: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
source: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -76,6 +76,11 @@ logsources:
service: printservice-admin
conditions:
EventChannel: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
EventChannel: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+6 -1
View File
@@ -200,7 +200,12 @@ logsources:
product: windows
service: smbclient-security
sources:
- "Microsoft-Windows-SmbClient/Security"
- "WinEventLog:Microsoft-Windows-SmbClient/Security"
windows-printservice-operational:
product: windows
service: printservice-operational
sources:
- "WinEventLog:Microsoft-Windows-PrintService/Operational"
windows-applocker:
product: windows
service: applocker
@@ -60,6 +60,11 @@ logsources:
service: printservice-admin
conditions:
winlog.channel: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
winlog.channel: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security
+5
View File
@@ -59,6 +59,11 @@ logsources:
service: printservice-admin
conditions:
winlog.channel: 'Microsoft-Windows-PrintService/Admin'
windows-printservice-operational:
product: windows
service: printservice-operational
conditions:
winlog.channel: 'Microsoft-Windows-PrintService/Operational'
windows-smbclient-security:
product: windows
service: smbclient-security