Skip to content

Instantly share code, notes, and snippets.

View moretalk's full-sized avatar
🎯
Focusing

Matthew Duggan moretalk

🎯
Focusing
View GitHub Profile
winlogbeat:
registry_file: "C:/Program Files/winlogbeat/winlogbeat.yml"
event_logs:
- name: Application
ignore_older: 72h
- name: System
ignore_older: 72h
- name: Security
ignore_older: 72h
---