Update win_susp_security_eventlog_cleared.yml

This commit is contained in:
S.kiran kumar
2020-10-11 19:48:07 +05:30
committed by GitHub
parent 672bf99c6b
commit 8a87fc35b2
@@ -12,7 +12,6 @@ detection:
EventID:
- 517
- 1102
- 104
condition: selection
falsepositives:
- Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)