You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
winlog.event_data.TaskContent XML data is not parsed in elasticsearch:
DOMAIN\user
Deze taak zorgt ervoor dat presentatie-instellingen worden uitgeschakeld als u zich opnieuw bij de computer aanmeldt.
\PresentationSettingsTurnOff_DOMAIN_USER
true
DOMAIN\USER
PT5S
IgnoreNew
false
false
true
false
false
PT10M
PT1H
true
false
true
true
true
false
false
PT72H
7
%windir%\system32\PresentationSettings.exe
/stop
DOMAIN\USER
InteractiveToken
LeastPrivilege
This change would start with elastic agent and/or winlogbeat, was thinking about a javascript processor that would run on the client:
function process(event) {
var xml = new XML(event.GetEvent());
var task = xml.Task;
however, this would also imply changes into the winlogbeat mappings.
Describe a specific use case for the enhancement or feature:
With the xml parsed we could create better exceptions in elasticsearch. Currently only the taskname is possible. While taskname is useful, i'm more interested in what commands the schedule task runs.
The text was updated successfully, but these errors were encountered:
Describe the enhancement:
https://www.elastic.co/guide/en/security/current/ .html
winlog.event_data.TaskContent XML data is not parsed in elasticsearch:
DOMAIN\user Deze taak zorgt ervoor dat presentatie-instellingen worden uitgeschakeld als u zich opnieuw bij de computer aanmeldt. \PresentationSettingsTurnOff_DOMAIN_USER true DOMAIN\USER PT5S IgnoreNew false false true false false PT10M PT1H true false true true true false false PT72H 7 %windir%\system32\PresentationSettings.exe /stop DOMAIN\USER InteractiveToken LeastPrivilegeThis change would start with elastic agent and/or winlogbeat, was thinking about a javascript processor that would run on the client:
function process(event) {
var xml = new XML(event.GetEvent());
var task = xml.Task;
}
however, this would also imply changes into the winlogbeat mappings.
Describe a specific use case for the enhancement or feature:
With the xml parsed we could create better exceptions in elasticsearch. Currently only the taskname is possible. While taskname is useful, i'm more interested in what commands the schedule task runs.
The text was updated successfully, but these errors were encountered: