Skip to content

Windows Integrations Different For the Same Log 100+ Differences #7174

@neu5ron

Description

@neu5ron
  1. Regex for Powershell Channel(s):

From Powershell Channel

Pattern detailRegex = /^([^:(]+)\(([^)]+)\)\:\s*(.+)?$/;

From Forwarded Powershell Channel

)

I would imagine the first one is the correct one per commit: 75c6fad
Also winlogbeat uses this one as well.

Same is also true for Powershell_Operational Regex

  1. 40 Differences for Security Channel
    There are over 40 differences between the Security Channel log and the same log within the Forwarded Channel despite them being the same log.

  2. 70 Differences for Sysmon Channel
    There are over 70 differences between the Sysmon Channel log and the same log within the Forwarded Channel despite them being the same log.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions