You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A service was installed in the system.
Subject:
Security ID: SYSTEM
Account Name: 824ZWL3$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Service Information:
Service Name: WpnUserService_a46b7
Service File Name: C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
Service Type: 0xE0
Service Start Type: 2
Service Account: LocalSystem
Here is a sample of what it looks like with downcase_description_keys = false
For some reason the fields ServiceName, ServiceType, and ServiceAccount all have an extra : at the end of the key name when downcase_description_keys is set to false. This causes issues when the logs are ingested into a SIEM. Does anyone know why this is?
The text was updated successfully, but these errors were encountered:
Here is a sample description for EventID 4697
Here is a sample of what it looks like with downcase_description_keys = false
Here is a sample of what it looks like with downcase_description_keys = true
For some reason the fields ServiceName, ServiceType, and ServiceAccount all have an extra
:
at the end of the key name when downcase_description_keys is set to false. This causes issues when the logs are ingested into a SIEM. Does anyone know why this is?The text was updated successfully, but these errors were encountered: