Youssef Mohammed
Results
3
comments of
Youssef Mohammed
and this is an example of one of the three events in splunk > 08/10/2016 02:57:28 PM > LogName=Security > SourceName=Microsoft Windows security auditing. > EventCode=4688 > EventType=0 > Type=Information...
I also tried to rename the fields to match the generic transformer constants (renamed some of the field including ( ex. eventtype to event_type) still nothing worked
find them at youtube https://www.youtube.com/watch?v=gLRmiX-LKJM&list=PLiv7oOe5j2E4BwlfDaBbLD_WaMHjnoiEN