Help Center
-
ArcSight
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
- Backup webservice
- CEF Key Names For Event Consumers
- CEF Key Names for Event Producers
- Client Authentication
- Custom Column with HTML and velocity
- Date Formats
- Filter include only PowerShell events
- Header Information
- How to disable ipv6 on logger or arcmc
- How to Increase the ArcSight connector character length of the rawEvent field
- Rules with velocity string variable
- Show hidden Resource Tree
- TestAlerts Connector events
- Using Extraprocessors in FlexConnectors
-
XSOAR
-
- Articles coming soon
- Articles coming soon
-
-
Docker
-
Elastic
-
- Articles coming soon
- Articles coming soon
-
-
Linux
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
MS Sentinel
-
- Articles coming soon
- Articles coming soon
-
-
Kubernetes
-
- Articles coming soon
- Articles coming soon
-
-
Development
-
Diverse
-
NNMi
-
- Articles coming soon
-
- Articles coming soon
- Articles coming soon
-
-
Virtualization
-
Vulnerability
-
Network
-
Microsoft
-
Pentest
-
- Articles coming soon
-
- Articles coming soon
- Articles coming soon
-
< All Topics
Print
Filter include only PowerShell events
Posted
Updated
ByLars Niklasson
Add this as a filter in agent.properties file:
*[System[Provider[@Name\=’Microsoft-Windows-PowerShell’ or @Name\=’PowerShell’]]]
Use \ for all = and !, for ex if you want not to include something: @Name\!\=’something’
Use Windows Event Viewer and create a filter and then switch to XML and copy the string in between <Select> and </Select>.
Table of Contents