I cannot seem to collect powershell logs. Can some...
# general
b
I cannot seem to collect powershell logs. Can someone let me know where my config is off?
Copy code
--disable_events=false
--disable_forensic=false
--enable_windows_events_publisher=true
--enable_windows_events_subscriber=true
--windows_events_channel=System,Application,Setup,Security,Microsoft-Windows-PowerShell
a
can you check the --help output? powershell should have its own flag if i am not mistaken
Powershell block logging should also be enabled from gpedit.msc
b
enabled block logging