Issue with gathered Event IDs
Hello,
We have installed the app and configured config.yaml to gather a couple of events. From some time we can see that l the logs with EventID 1 are being collected, which we did not configure.
Could you please help me understand on what basis this event is collected?
Regards,
@paulinacisek92 can you share your config.yaml?
Hello Eric,
Did you have time to review this issue?
Kind regards, Paulina
sob., 16 lip 2022 o 13:49 Paulina Cisek @.***> napisał(a):
Hi Eric,
Thanks for response, please see attached file.
Kind regards, Paulina
śr., 13 lip 2022 o 18:04 Eric @.***> napisał(a):
@paulinacisek92 https://github.com/paulinacisek92 can you share your config.yaml?
— Reply to this email directly, view it on GitHub https://github.com/vector-sec/TA_ETW/issues/8#issuecomment-1183407518, or unsubscribe https://github.com/notifications/unsubscribe-auth/ALAZ7YMZUCZJJILIFNC3ZV3VT3SHBANCNFSM53OKIRIA . You are receiving this because you were mentioned.Message ID: @.***>
-- Paulina Cisek
-- Paulina Cisek
@paulinacisek92 are you able to share your config file?
Hello,
I have shared IT in my previous email.
Kind regards, Paulina
śr., 13 lip 2022, 18:04 użytkownik Eric @.***> napisał:
@paulinacisek92 https://github.com/paulinacisek92 can you share your config.yaml?
— Reply to this email directly, view it on GitHub https://github.com/vector-sec/TA_ETW/issues/8#issuecomment-1183407518, or unsubscribe https://github.com/notifications/unsubscribe-auth/ALAZ7YMZUCZJJILIFNC3ZV3VT3SHBANCNFSM53OKIRIA . You are receiving this because you were mentioned.Message ID: @.***>
@paulinacisek92 I do not see it in the issue on GitHub, is it possible to attach it there?
Hi Eric,
Thanks for response, please see attached file.
Kind regards, Paulina
śr., 13 lip 2022 o 18:04 Eric @.***> napisał(a):
@paulinacisek92 https://github.com/paulinacisek92 can you share your config.yaml?
— Reply to this email directly, view it on GitHub https://github.com/vector-sec/TA_ETW/issues/8#issuecomment-1183407518, or unsubscribe https://github.com/notifications/unsubscribe-auth/ALAZ7YMZUCZJJILIFNC3ZV3VT3SHBANCNFSM53OKIRIA . You are receiving this because you were mentioned.Message ID: @.***>
-- Paulina Cisek