-
Using current Security Onion 2.4.80 Standalone. Elastic Agent on Integration on current Windows 11Pro 23H2. Windows has the Endpoints-Initial Agent Policy including windows-endpoints (v1.38.0) and windows-defender integrations. Powershell events are not being collected in the Window Elastic Agent so they are not passed to SO. Any idea why? |
Beta Was this translation helpful? Give feedback.
Answered by
hotcobra
Jul 18, 2024
Replies: 1 comment 3 replies
-
Are other logs from the agent being ingested into SO? Do you see any issues in the agent log? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
No errors or warnings in the Win11 endpoint logs. However, I'm a dummy since I just found them in Elastic-Dashboards. They are coming across with filebeat. There is a Windows PowerShell dashboard in Elastic that I can use.