2023-05-12 11:47:01 +00:00
|
|
|
##RDP
|
2022-05-17 10:14:59 +00:00
|
|
|
source: wineventlog
|
|
|
|
event_channel: Security
|
|
|
|
event_ids:
|
|
|
|
- 4625
|
|
|
|
- 4623
|
|
|
|
event_level: information
|
|
|
|
labels:
|
2023-05-12 11:47:01 +00:00
|
|
|
type: eventlog
|
|
|
|
---
|
|
|
|
##Firewall
|
|
|
|
filenames:
|
|
|
|
- C:\Windows\System32\LogFiles\Firewall\pfirewall.log
|
|
|
|
labels:
|
|
|
|
type: windows-firewall
|
|
|
|
---
|
|
|
|
##SQL Server
|
|
|
|
source: wineventlog
|
|
|
|
event_channel: Application
|
|
|
|
event_ids:
|
|
|
|
- 18456
|
|
|
|
event_level: information
|
|
|
|
labels:
|
|
|
|
type: eventlog
|
|
|
|
---
|
|
|
|
##IIS
|
|
|
|
use_time_machine: true
|
|
|
|
filenames:
|
|
|
|
- C:\inetpub\logs\LogFiles\*\*.log
|
|
|
|
labels:
|
|
|
|
type: iis
|