WMI Temporary Event Subscription
Description
This search looks for the creation of WMI temporary event subscriptions.
Content Mapping
This content is not mapped to any local saved search. Add mapping
Help |
---|
WMI Temporary Event Subscription HelpTo successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. |
Search |
---|
Open in Search |