palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.22k stars 267 forks source link

Add subscriptions for ADFS #1

Closed cryps1s closed 6 years ago

cryps1s commented 7 years ago

Add WEF subscription for Active Directory Federated Services operational and debug logs.

cryps1s commented 6 years ago

WinEventLog://AD FS/Admin - All Events WinEventLog://Duo Authentication for AD FS - All Events WinEventLog://AD FS Tracing/Debug - All Events Security - Whitelist for SourceName=^AD FS Auditing$

cryps1s commented 6 years ago

Handled via branch: https://github.com/palantir/windows-event-forwarding/pull/13