0a992d716a
* update syntax to reflect eql changes * use more case-insensitivity * comment out missing fields for winlogbeat compatibility