<Event xmlns="*****">
- <System>
<Provider Name="Microsoft-Windows-Sysmon" Guid="***" />
<EventID>22</EventID>
<Version>5</Version>
<Level>4</Level>
<Task>22</Task>
<Opcode>0</Opcode>
<Keywords>***</Keywords>
<TimeCreated SystemTime="2024-08-01T19:13:38.674474200Z" />
<EventRecordID>32857</EventRecordID>
<Correlation />
<Execution ProcessID="8704" ThreadID="9280" />
<Channel>Microsoft-Windows-Sysmon/Operational</Channel>
<Computer>***</Computer>
<Security UserID="****" />
</System>
- <EventData>
<Data Name="RuleName">-</Data>
<Data Name="UtcTime">2024-08-01 19:13:37.884</Data>
<Data Name="ProcessGuid">***</Data>
<Data Name="ProcessId">****</Data>
<Data Name="QueryName">*****</Data>
<Data Name="QueryStatus">0</Data>
<Data Name="QueryResults">172.16.20.143;</Data>
<Data Name="Image"****
<Data Name="User">***</Data>
</EventData>
</Event>

