Configuration/Definitions/LogClearSystem.json
{ "SearchDefinition": { "LogClearSystem": { "Events": { "Fields": { "Computer": "Computer", "Action": "Action", "Date": "Date", "Who":"Who", "UserID":"UserId", "SubjectUserName": "SubjectUserName", "SubjectDomainName": "SubjectDomainName", "MachineName":"ObjectAffected", "NoNameB1":"EventSource", "NoNameB5":"EventAction", "NoNameB4":"EventLevel", "ID": "Event ID", "RecordID": "Record ID", "GatheredFrom": "Gathered From", "GatheredLogName": "Gathered LogName" }, "Events": 104, "IgnoreWords": {}, "LogName": "System", "SortBy": "When", "Enabled": true }, "Enabled": true } }, "LogName": "WEC5-Log-Deletion-System" } |