Specified source to prevent EventID collisions

Issue #263
This commit is contained in:
Thomas Patzke 2019-04-01 23:45:55 +02:00
parent 0419ff215a
commit 8e854b06f6

View File

@ -13,6 +13,7 @@ logsource:
detection:
selection:
EventID: 104
Source: Microsoft-Windows-Eventlog
condition: selection
falsepositives:
- Unknown