Update McAfeeNSPEvent.txt
This commit is contained in:
Родитель
2e53f50b33
Коммит
d571fb9f7b
|
@ -3,7 +3,7 @@
|
|||
// Function usually takes 10-15 minutes to activate. You can then use function alias from any other queries (e.g. McAfeeNSPEvent | take 10).
|
||||
// Reference : Using functions in Azure monitor log queries : https://docs.microsoft.com/azure/azure-monitor/log-query/functions
|
||||
Syslog
|
||||
| where ProcessName == "SyslogAlertForwarderNSP"
|
||||
| where ProcessName == "SyslogAlertForwarderNSPTest"
|
||||
| extend EventVendor = 'McAfee'
|
||||
| extend EventProduct = 'Network Security Manager'
|
||||
| extend EventData = split(SyslogMessage, "|")
|
||||
|
|
Загрузка…
Ссылка в новой задаче