Skip to content

Dashboard issues with "[Windows AppLocker] Audited and Blocked Applications" dashboard as provided by "Windows" integration 1.44.1 #8969

@eriroley

Description

@eriroley

there appears to be an insufficient filter on the "Top File names by Application Execution Count" (especially since I only have a single host that is reporting AppLocker events right now)
image
When I examine the data in Discover, I see that it is looking in logs-* for "File.name":*
image

I suggest adding the filter for "event.provider:Microsoft-Windows-Applocker" (which I had to edit in Lens)
image

A similar filter probably needs to be added to file publishers based on FQBN by application execution count, and honestly, probably all of the panels

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions