Hello Gastón
Thank you so much for your help.
However, the test results do not work as expected.
Best regards,
Ethan Thompson
## test 1 ##
1. Only "system", "application" channel names are detected.
- data.win.system.channel: System, data.win.system.channel: Application
2. The entire "security" channel is not detected.
<localfile>
<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/System[EventID != 5158 and EventID != 4957 and EventID != 5152 and
EventID != 5157 and EventID != 5031 and EventID != 1001]</query>
</localfile>
<localfile>
<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/EventData/Data[@Name="objectName"] != "LSM"</query>
</localfile>
## test 2 ##
1. Same as the result of "test 1"
<localfile>
<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/System[EventID != 5158 and EventID != 4957 and EventID != 5152 and
EventID != 5157 and EventID != 5031] and
Event/EventData/Data[@Name="ObjectName"] != "LSM"</query>
</localfile>
## test 3 ##
1. In addition to "System" and "Application", some logs in the "Security" channel are also detected.
2. However, common event IDs of "secure" channels such as 4724 and 4734 are not being detected.
<localfile>
<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/System[EventID != 5158 and EventID != 4957 and EventID != 5152 and
EventID != 5157 and EventID != 5031 and EventID != 1001]</query>
</localfile>
<localfile>
<location>Security</location>
<log_format>eventchannel</log_format>
<query>Event/EventData/Data[@Name="objectServer"] != "SC Manager"</query>
</localfile>
2023년 3월 31일 금요일 오전 3시 20분 22초 UTC+9에 Gastón Palomeque님이 작성: