there appears to be an insufficient filter on the "Top File names by Application Execution Count" (especially since I only have a single host that is reporting AppLocker events right now)

When I examine the data in Discover, I see that it is looking in logs-* for "File.name":*

I suggest adding the filter for "event.provider:Microsoft-Windows-Applocker" (which I had to edit in Lens)

A similar filter probably needs to be added to file publishers based on FQBN by application execution count, and honestly, probably all of the panels
there appears to be an insufficient filter on the "Top File names by Application Execution Count" (especially since I only have a single host that is reporting AppLocker events right now)


When I examine the data in Discover, I see that it is looking in logs-* for "File.name":*
I suggest adding the filter for "event.provider:Microsoft-Windows-Applocker" (which I had to edit in Lens)

A similar filter probably needs to be added to file publishers based on FQBN by application execution count, and honestly, probably all of the panels