Remove missing fields in Windows Event Log Cleared detection#4001
Remove missing fields in Windows Event Log Cleared detection#4001AndreiBanaru wants to merge 2 commits intosplunk:developfrom
Conversation
|
Bummer, I see the build failed since
|
|
I could do a: right before the |
This is not an issue, we could remove these from the required fields, if they are not filled. I will investigate and apply the changes accordingly. |
As described in #4000, I believe these fields should be removed since the aggregation will miss results for
EventCode=104.