-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
x-pack/winlogbeat/module/sysmon: add eventid 26 handler #29957
Conversation
This pull request does not have a backport label. Could you fix it @efd6? 🙏
NOTE: |
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
💚 Build Succeeded
Expand to view the summary
Build stats
Test stats 🧪
💚 Flaky test reportTests succeeded. 🤖 GitHub commentsTo re-run your PR in the CI, just comment with:
|
(cherry picked from commit 33acb3c)
) (cherry picked from commit 33acb3c) Co-authored-by: Dan Kortschak <[email protected]>
What does this PR do?
This change adds support for sysmon event ID 26; FileDeleteDetected.
Why is it important?
See linked issue #26280.
Checklist
CHANGELOG.next.asciidoc
orCHANGELOG-developer.next.asciidoc
.Author's Checklist
How to test this PR locally
Related issues
Use cases
See linked issue.
Screenshots
Test event 1:
Test event 2:
Logs
See screenshot above.