-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support for Applications and Services Logs #25
Comments
This issue is blocker for me also :( |
This issue makes impossible to recieve logs from Printer-Spooler, DHCP, Operational and many other channels on latest Windows (workstation) and Windows Server versions. |
So I have spent some time looking into this and I have found that this is parsing the windows evt logs. By Calling " Unless someone refactors this fully I am unsure if it will ever support the newer evtx format. |
We use Sysmon which logs Event Logs to the "Microsoft-Windows-Sysmon/Operational" Channel. Of which, the Regkey is in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels" as opposed to "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog"
is it possible to add support for both paths so that we can use logs in both?
The text was updated successfully, but these errors were encountered: