Skip to content

Eid2 filter with "\n" #12

@renshareck

Description

@renshareck

there is "\n" after "SysmonCreateFileTime.txt" in sysmon config file that causes no-working of Event2.

	<!-- -eid 2 is Working -->
	<FileCreateTime onmatch="include">
		<Image name="SysmonSimulator FileCreateTime modification Simulation for SysmonCreateFileTime.txt" condition="end with">SysmonSimulator.exe</Image>
		<TargetFilename condition="end with">SysmonCreateFileTime.txt
		</TargetFilename>

	</FileCreateTime>

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions