Re: [ossec-list] Missing EventData - Data fields in archives and alerts

2017-08-11 Thread dan (ddp)
On Fri, Aug 11, 2017 at 3:16 PM, Tibor Luth wrote: > Dear Group! > > I've tried to parse MSExchande Management / MSExchange Cmdlet logs from > Windows Event Log from its own log source. I've also enabled logall option. > Logtest working. Im currently getting and parsing the logs but I miss > addit

[ossec-list] Missing EventData - Data fields in archives and alerts

2017-08-11 Thread Tibor Luth
Dear Group! I've tried to parse MSExchande Management / MSExchange Cmdlet logs from Windows Event Log from its own log source. I've also enabled logall option. Logtest working. Im currently getting and parsing the logs but I miss additional informations. Seems like the log is incomplete also in