Created May 19, 2022 17:47
Winlogbeat script to log specific event IDs
- name: Security
ignore_older: 1h
- script:
lang: javascript
source: |
var console = require("console");
var ids = {
4728: null,
4729: null,
4732: null,
4733: null,
4756: null,
4757: null,
4758: null,
function process(evt) {
var eventID = evt.Get("winlog.event_id");
if (ids[eventID] !== undefined) {"EVENT_ID_FOUND: Read event ID", eventID);
evt.AppendTo("tags", "EVENT_ID_FOUND");
- script:
lang: javascript
id: security
file: "C:/Program Files/Winlogbeat/module/security/config/winlogbeat-security.js"
