ArcSight requires Microsoft-Windows-Security-Auditing:(EventCode) to properly categorize. What I am looking to do is like this:
deviceEventClassId=Microsoft-Windows-Security-Auditing:($1)
whereas `$1` is equal to EventCode
so that Arcsight will import something like:
Microsoft-Windows-Security-Auditing:5663
↧