Merge pull request #13409 from Security-Onion-Solutions/fix/elastic_fleet_defender

Fix defender winlog name change
This commit is contained in:
weslambert
2024-07-30 15:47:45 -04:00
committed by GitHub

View File

@@ -11,11 +11,11 @@
"winlogs-winlog": {
"enabled": true,
"streams": {
"winlog.winlog": {
"winlog.winlogs": {
"enabled": true,
"vars": {
"channel": "Microsoft-Windows-Windows Defender/Operational",
"data_stream.dataset": "winlog.winlogs",
"data_stream.dataset": "winlog.winlog",
"preserve_original_event": false,
"providers": [],
"ignore_older": "72h",