{"win":{"system":{"providerName":"Microsoft-Windows-Security-Auditing","providerGuid":"{54849625-5478-4994-a5ba-3e3b0328c30d}","eventID":"4699","version":"1","level":"0","task":"12804","opcode":"0","keywords":"0x8020000000000000","systemTime":"2022-11-29T10:03:14.868233700Z","eventRecordID":"580818","processID":"660","threadID":"4616","channel":"Security","computer":"SOC-DC01.soc-ngway.local","severityValue":"AUDIT_SUCCESS","message":"\"A scheduled task was deleted.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-598632658-3456686301-2170191157-500\r\n\tAccount Name:\t\tadministrator\r\n\tAccount Domain:\t\tNGWSOC\r\n\tLogon ID:\t\t0x10176531\r\n\r\nTask Information:\r\n\tTask Name: \t\t\\testone\r\n\tTask Content: \t\t\r\n\r\nOther Information:\r\n\tProcessCreationTime: \t\t2814749767115427\r\n\tClientProcessId: \t\t\t5260\r\n\tParentProcessId: \t\t\t5904\r\n\tFQDN: \t\t0\r\n\t\""},"eventdata":{"subjectUserSid":"S-1-5-21-598632658-3456686301-2170191157-500","subjectUserName":"administrator","subjectDomainName":"NGWSOC","subjectLogonId":"0x10176531","taskName":"\\\\testone","clientProcessStartKey":"2814749767115427","clientProcessId":"5260","parentProcessId":"5904","rpcCallClientLocality":"0","fQDN":"SOC-DC01.soc-ngway.local"}}}