Skip to content

[windows] AppLocker Events for Windows Integration #6979

@nicpenning

Description

@nicpenning

The plan is to add AppLocker events into the current Windows integration as additional data streams so that users will not have to use the Custom Windows Integration and have to maintain their own events.

This will help simplify some use cases out there, where AppLocker events are needed. Today, this requires 4 Custom Windows Integrations added to a policy.

The 4 channels that will be added over time are:

AppLocker

image

Field mappings, pipelines and of course dashboards will be in the works.

This issue will track the development of these new data streams.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Integration:windowsWindowsNew IntegrationIssue or pull request for creating a new integration package.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions