Change ParentCommandLine: - 'setupapi.dll*InstallHinfSection' to ParentCommandLine|contains|all: - 'setupapi.dll' - 'InstallHinfSection' because some LM/SIEM systems don't process '*' as Splunk or Elasticsearch