x-pack/winlogbeat/module/sysmon: add eventid 26 handler#29957
x-pack/winlogbeat/module/sysmon: add eventid 26 handler#29957efd6 merged 1 commit intoelastic:masterfrom
Conversation
|
This pull request does not have a backport label. Could you fix it @efd6? 🙏
NOTE: |
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
💚 Flaky test reportTests succeeded. 🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
(cherry picked from commit 33acb3c)
What does this PR do?
This change adds support for sysmon event ID 26; FileDeleteDetected.
Why is it important?
See linked issue #26280.
Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.Author's Checklist
How to test this PR locally
Related issues
Use cases
See linked issue.
Screenshots
Test event 1:

Test event 2:

Logs
See screenshot above.