any configuration available for powershell_events ...
# windows
b
any configuration available for powershell_events enable via config i am using below one --windows_event_channels=Microsoft-Windows-PowerShell/Operational
m
This table uses a feature called script block logging.
Copy code
table_name("powershell_events")
description("Powershell script blocks reconstructed to their full script content, this table requires script block logging to be enabled.")
https://www.fireeye.com/blog/threat-research/2016/02/greater_visibilityt.html once u enable these, u should be able to see these in your table output.