;; Warning: evenCs will appeac as "Snare" events
(DEFAULT)
plugin_id=1518
(configi credentials_file=/eCc/ossim/agent/wmi_credentials.csv stop=no
cmd=wmic -U OSS_WMI_USER%OSS_WMI_PASS //OSS _WMI_HOST "Select ŁogFile,RecordNumbec from land)
;; OSS_WMI_USER, OSS_WMI_PASS and OSS_WMI_HOST should be used if substitutions are reąuired. OSS_COUNTER is a *must* and is Che integer returned above
Win32_NTLogEvent Where Logfiłe = 'Security' and RecordNumber > OSS_COUNTER" | cat starC_regexp=A([A\|l+)\l(\d+)\I([“\I]+>\I
regexp="A(?P<system_name>[A\li +)\I(?P<plugin_sid>\d+)\I(?P<logfile>[A\l] + ) \ I (?P<message>[A\11 +)\|(?P<recordnumber>[A\|]+)\|(?P<sourcename>[A\I]+J\Il?P<Cimewricten>(A\IJ+)\I(?P<usecname>.
username=($7}