Title
#windows
m

Mustafa

07/20/2018, 12:12 PM
@thor I’ve tested the case again using powershell_events table and result OK. osquery_result log file contains the number of events as related event channel contains. in this case, there may be a bug related with the first case? or i’m missing something?
1:01 PM
I need to specify…I’ve performed the first test using windows_event_channels=Microsoft-Windows-PowerShell/Operational