Files
blue-team-tools/tools/config/elk-windows.yml
T
2017-03-14 23:22:32 +01:00

20 lines
407 B
YAML

logsources:
windows:
product: windows
index: logstash-windows-*
windows-application:
product: windows
service: application
conditions:
EventLog: Application
windows-security:
product: windows
service: security
conditions:
EventLog: Security
windows-sysmon:
product: windows
service: sysmon
conditions:
EventLog: Microsoft-Windows-Sysmon