Files
blue-team-tools/tools/config/elk-sysmon.yml
T
2017-03-14 23:22:32 +01:00

8 lines
150 B
YAML

logsources:
sysmon:
product: windows
service: sysmon
index: logstash-windows-*
conditions:
EventLog: Microsoft-Windows-Sysmon