title: Logsource to LogName mappings for PowerShell backend order: 20 backends: - powershell logsources: windows-application: product: windows service: application conditions: LogName: 'Application' windows-security: product: windows service: security conditions: LogName: 'Security' windows-system: product: windows service: system conditions: LogName: 'System' windows-sysmon: product: windows service: sysmon conditions: LogName: 'Microsoft-Windows-Sysmon/Operational' windows-powershell: product: windows service: powershell conditions: LogName: 'Microsoft-Windows-PowerShell/Operational' windows-classicpowershell: product: windows service: powershell-classic conditions: LogName: 'Windows PowerShell' windows-taskscheduler: product: windows service: taskscheduler conditions: LogName: 'Microsoft-Windows-TaskScheduler/Operational' windows-wmi: product: windows service: wmi conditions: LogName: 'Microsoft-Windows-WMI-Activity/Operational' windows-dns-server: product: windows service: dns-server category: dns conditions: LogName: 'DNS Server' windows-dns-server-audit: product: windows service: dns-server-audit conditions: LogName: 'Microsoft-Windows-DNS-Server/Audit' windows-driver-framework: product: windows service: driver-framework conditions: LogName: 'Microsoft-Windows-DriverFrameworks-UserMode/Operational' windows-ntlm: product: windows service: ntlm conditions: LogName: 'Microsoft-Windows-NTLM/Operational' windows-dhcp: product: windows service: dhcp conditions: LogName: 'Microsoft-Windows-DHCP-Server/Operational'