Data Source: Sysmon EventID 26

Description

Data source object for Sysmon EventID 26

Details

Property Value
Source XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sourcetype xmlwineventlog
Separator EventID

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
</div>

Source: GitHub | Version: 1