1 Reply Latest reply on Jul 5, 2017 1:11 AM by abanaru

    PowerShell Log Parsing

    anton2016

      I've started to test PowerShell logging within the SIEM and it doesn't look like the events are being parsed properly, here is the text from an Event (800):

       

      ps2.png

      And here is how the SIEM sees it:

       

      ps2.png

       

      The packet has the data I'm looking for (blue highlight box) :

       

      ps3.png

       

      Is this a parsing issue or just how the SIEM sees these types of events?