plaso
plaso copied to clipboard
Make Windows EventLog tagging rules more robust
Currently Windows EventLog tagging rules are based on event source name and identifier. However per https://winevt-kb.readthedocs.io/en/latest/sources/eventlog-providers/index.html is it evident that EventLog can have multiple names and/or an identifier for the same provider (https://winevt-kb.readthedocs.io/en/latest/sources/eventlog-providers/Provider-Microsoft-Windows-COMRuntime.html).
Check/Change the rules to ensure all the known event source names and identifiers are included in the tagging rules.