Comments (2)
I don't think this is correct as this page shows this event in the Microsoft-Windows-SoftwareRestrictionPolicies channel: http://intelligentsystemsmonitoring.com/knowledgebase/windows-operating-system/event-id-software-restriction-policy-notification-13844/#:~:text=Windows%20Operating%20System-,Event%20ID%20865%20%E2%80%94%20Software%20Restriction%20Policy%20Notification,not%20allowed%20by%20the%20policy.
from windows-event-forwarding.
I have checked this in the log manifest on a test system , all referenced events appear in the Application channel. Also as @appelboom has pointed out, the Subscription Query is incorrect. The first selector (*[Application[
) in the XPath query string does not reference the channel, but the system header of the event XML. This header, including the provider specification, is always located in the System
element. Therefore the query should be as follows:
*[System[Provider[@Name='Microsoft-Windows-SoftwareRestrictionPolicies'] and (EventID=865 or EventID=866 or EventID=867 or EventID=868 or EventID=882)]]
from windows-event-forwarding.
Related Issues (20)
- Don't hide Microsoft signed entries in AutorunsToWinEventLog HOT 1
- Wrapping of Image_Path and Hashes HOT 5
- Recommended WEC Server Hardware Specifications HOT 4
- DUMMY_EVENT & DUMMY_TEMPLATE in custom channels HOT 2
- character encoding problems with some files HOT 2
- Server 2016 collector woe HOT 1
- wecutil ss error x057 HOT 4
- Authentication suppression rule may be a little aggressive for some HOT 1
- Are all servers/ workstations supposed to subscribe to all subscriptions? HOT 3
- wecsvc stops working after a while HOT 26
- EventID 4648 not included
- WEC won't forward events to self if WinRM GPO doesn't include IPv6 filter HOT 3
- Collector Server HOT 3
- Push for performance improvement HOT 1
- Event Providers and Channels - DB Audit Events
- Download of Autorunsc64.exe Incorrectly Uses HTTPS HOT 3
- Add WEF subscription for TPM-WMI HOT 2
- Add WEF Subscriptions for Exploit Guard ASR HOT 1
- Add WEF Subscriptions for Exploit Guard HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from windows-event-forwarding.