0xrawsec / whids

Open Source EDR for Windows
https://rawsec.lu
GNU Affero General Public License v3.0
1.14k stars 138 forks source link

Whids Stopping Logging #125

Closed badboycxcc closed 2 years ago

badboycxcc commented 2 years ago

Whids Stopping Logging Only log from July 31st to August 1st, today is August 4th

os: windows 11

image

badboycxcc commented 2 years ago

Whids log

2022/08/01 21:18:32 INFO - Number of rules loaded in engine: 132
2022/08/01 21:18:32 INFO - Update routine running: false
2022/08/01 21:18:32 INFO - Dump forwarding routine running: false
2022/08/01 21:18:32 INFO - Command runner routine running: false
2022/08/01 21:18:32 INFO - Sysmon archived files cleanup routine running: true
2022/08/01 21:18:32 INFO - Starting routine to cleanup Sysmon archived files
2022/08/01 21:18:32 INFO - Starting archive cleanup loop for directory: C:\Sysmon\
2022/08/01 21:18:33 ERROR - Failed to subscribe to channel "Microsoft-Windows-Windows Defender/Operational": The specified channel could not be found.
qjerome commented 2 years ago

Hey @badboycxcc,

Which version are you using ? From the logs I guess you are using the latest stable release, could you please confirm ?

badboycxcc commented 2 years ago

嘿@badboycxcc,

您使用的是哪个版本? 从日志中我猜你正在使用最新的稳定版本,你能确认一下吗?

V1.7.0 .I use this version

qjerome commented 2 years ago

Thank you for your feedback. Can you please try to use the latest beta release, which is more stable than latest stable release >< ! Please don't forget to tell me whether you still get the issue with the latest beta release.

badboycxcc commented 2 years ago

ok

qjerome @.***> 于 2022年8月5日周五 上午3:50写道:

Thank you for your feedback. Can you please try to use the latest beta release, which is more stable than latest stable release >< ! Please don't forget to tell me whether you still get the issue with the latest beta release.

— Reply to this email directly, view it on GitHub https://github.com/0xrawsec/whids/issues/125#issuecomment-1205701844, or unsubscribe https://github.com/notifications/unsubscribe-auth/ARFYSVNYBM3F3NEW6T4SN5LVXQNI5ANCNFSM55QW4SUA . You are receiving this because you were mentioned.Message ID: @.***>