Skip to content

[winlogbeat] Fix UAC translation values #36999

@bhapas

Description

@bhapas

Few users reported that winlog.event_data.NewUACList shows incorrect translation for the User Access Control values and there is a discrepancy with what is generated from Powershell too.

From the official documentation the values should be https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-samr/4df07fab-1bbc-452f-8e92-7853a3c7e380

image

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions