pC_microsoftevsecuritykvlogclearsuccess11022.md

December 5, 2023 ยท View on GitHub

Parser Content

{
Name = microsoft-evsecurity-kv-log-clear-success-1102-2
TimeFormat = "epoch_sec"
Conditions = [
  """EventIDCode=1102"""
  """The audit log was cleared"""
]
DupFields = [ "host->src_host" ]
ParserVersion = "v1.0.0"


}