Stay organized with collections Save and categorize content based on your preferences.

Change log for WINEVTLOG_XML

Date Changes
2023-01-15 Enhancement:
- For "EventId": 8004.
- Mapped "Task" to "target.resource.type".
- Mapped "DomainName" to "principal.administrative_domain".
- Mapped "Keywords","Channel","Level","SChannelName","SChannelType","Opcode" to "".
- Mapped "ThreadID" to "target.resource.attribute.labels".
2023-01-13 Enhancement:
- Handled unparsed logs having "EventId": 5001, 5007.
- Mapped "ProcessID" to "target.process.pid".
- Mapped "ProviderGuid" to "target.resource.product_object_id".
- Mapped "UserID" to "target.user.windows_sid".
- Mapped "ProductName" and "ProductVersion" to "metadata.product_version".
- Mapped "metadata.event_type" to "STATUS_UPDATE".
2022-12-06 Enhancement:
- Handled unparsed logs having "EventId": 8004.