Title
#windows
theopolis

theopolis

07/24/2020, 1:34 AM
here's a great new table that allows you to directly query the Windows Event Log. https://github.com/osquery/osquery/pull/6563 Since we already have a
windows_events
table that collects events in real time, what should this on-demand table be called? Perhaps
windows_eventlog
or
windows_eventslog
? Other ideas or preference?
zwass

zwass

07/24/2020, 3:08 AM
windows_eventlog
sounds good to me. This is a great addition, thank you @Akshay Kumar (I think?)
a

Akshay Kumar

07/24/2020, 1:08 PM
Thanks @zwass for the suggestion. 🙂
Magneto

Magneto

07/27/2020, 11:40 PM
+1 for "windows_eventlog"