Update FileEventMicrosoftSysmonFileDeleted.yaml
deleting "\Event"
This commit is contained in:
Родитель
3cf5b77f02
Коммит
72aa06ba92
|
@ -12,7 +12,7 @@ References:
|
|||
Link: https://aka.ms/AzSentinelFileEventDoc
|
||||
- Title: ASIM
|
||||
Link: https://aka.ms/AzSentinelNormalization
|
||||
Description: ASIM Sysmon/Event File Deletion Event Parser (event number 23) from "Event" and "WindowsEvent" tables.
|
||||
Description: ASIM Sysmon File Deletion Event Parser (event number 23) from "Event" and "WindowsEvent" tables.
|
||||
ParserName: vimFileEventMicrosoftSysmonDeleted
|
||||
ParserQuery: |
|
||||
let Sysmon23_26_Event=(){
|
||||
|
@ -100,4 +100,4 @@ ParserQuery: |
|
|||
| project-away hash, hash_algorithm, hash_value
|
||||
};
|
||||
union isfuzzy=true Sysmon23_26_Event,
|
||||
Sysmon23_26_WindowsEvent
|
||||
Sysmon23_26_WindowsEvent
|
||||
|
|
Загрузка…
Ссылка в новой задаче