Microsoft Windows
How to get Windows data into your Splunk deployment
Windows data you can collect
Link to supporting documentation
Powershell
[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
renderXml = false
index = wineventlog
source = Microsoft-Windows-PowerShell/Operational
sourcetype = WinEventLog
evt_resolve_ad_obj = 1Microsoft Defender XDR
Last updated