keko
10/01/2019, 1:41 AMwindows_event_channels: 'System,Application,Setup,Security,Microsoft-Windows-Sysmon/Operational'
zwass
10/02/2019, 1:00 AMkeko
10/07/2019, 9:10 PMsource
in Fleet when I query my host, so I figured I might have done the config wrong.
apiVersion: 1
kind: options
spec:
config:
options:
windows_event_channels: 'System,Application,Setup,Security,Microsoft-Windows-Sysmon/Operational'
System,Application,Setup,Security
are under 'Windows Logs', while Microsoft-Windows-Sysmon/Operational
is under 'Applications and Service Logs'