is it possible to exclude the AppLocker test events, that Windows generates loads of, from being forwarded to our Windows event collector? Our sysmonconf file is the Swift sysmon.xml
the event XML has this information in the "filepath" and "fullfilepath" sections. eg
is it possible to exclude the AppLocker test events, that Windows generates loads of, from being forwarded to our Windows event collector? Our sysmonconf file is the Swift sysmon.xml
the event XML has this information in the "filepath" and "fullfilepath" sections. eg