Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
Example:
search_multiple:C:\Windows\explorer.exe`Integritylevel: system~Microsoft-Windows-Sysmon/Operational~1
show as ONLY "C:\Windows\explorer.exe" in debug function under "Search_Rule".
Example: search_multiple:C:\Windows\explorer.exe`Integritylevel: system~Microsoft-Windows-Sysmon/Operational~1 show as ONLY "C:\Windows\explorer.exe" in debug function under "Search_Rule".
Possible is in function to do multiSearch.