olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.13k stars 178 forks source link

Threat Hunting trigger overview is full of 0 #121

Open javieru14 opened 11 months ago

javieru14 commented 11 months ago

Hi!

Threat Hunting trigger overview About this app Indexes

This is my C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf

[WinEventLog://Microsoft-Windows-Sysmon/Operational] disabled = false renderXml = 1 source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational index = windows

[WinEventLog://System] disabled = false renderXml = 0 index = windows

[WinEventLog://Application] disabled = false renderXml = 0 index = windows

[WinEventLog://Security] disabled = false renderXml = 0 index = windows

[WinEventLog://Microsoft-Windows-PowerShell/Operational] disabled = false renderXml = 0 index = windows

[WinEventLog://Microsoft-Windows-Windows Firewall With Advanced Security/Firewall] disabled = false renderXml = 0 index = windows