Hi, is there a way to get process events in windows using osqueryd? I know that we can use process_eventstable for Linux, but is there something similar for windows too?
s
seph
07/14/2021, 10:52 AM
There's an event in the event log. You can enable that and look for it.
It would be great to have a blog article where someone walks through the end to end of enabling the right windows event channels for process auditing and shows how to tweak and optimize this data.
m
MoodyMudit
07/26/2021, 2:53 PM
It would be great if there was such a walkthrough. Currently, I just wanted to collect process_events, but looks like this table collects all types of logs.