Configuration/Definitions/OSCrash.json
{ "SearchDefinition": { "OSCrash": { "Events": { "Fields": { "Computer": "Computer", "Date": "Date", "MachineName": "ObjectAffected", "NoNameB3":"EventLevel", "NoNameB4":"EventActionDetails", "EventAction": "EventAction", "ID": "Event ID", "RecordID": "Record ID", "GatheredFrom": "Gathered From", "GatheredLogName": "Gathered LogName" }, "Overwrite": { "EventAction#1": [ "Event ID", 6008, "System Crash" ] }, "Ignore": {}, "Events": [ 6008 ], "IgnoreWords": {}, "LogName": "System", "Enabled": true }, "Enabled": true } }, "LogName": "WEC5-Operating-System" } |