palantir / windows-event-forwarding

A repository for using windows event forwarding for incident detection and response
Other
1.23k stars 268 forks source link

Fix query for logging event id 5138 as intended instead of 5178 #53

Closed dboekhout closed 2 years ago

palantirtech commented 3 years ago

Thanks for your interest in palantir/windows-event-forwarding, @dboekhout! Before we can accept your pull request, you need to sign our contributor license agreement - just visit https://cla.palantir.com/ and follow the instructions. Once you sign, I'll automatically update this pull request.