pC_microsoftevsecuritykvlogclearsuccess11022.md
December 5, 2023 ยท View on GitHub
Parser Content
{
Name = microsoft-evsecurity-kv-log-clear-success-1102-2
TimeFormat = "epoch_sec"
Conditions = [
"""EventIDCode=1102"""
"""The audit log was cleared"""
]
DupFields = [ "host->src_host" ]
ParserVersion = "v1.0.0"
}