Skip to content

Commit 3f7c268

Browse files
committed
fixed issue with identifying proper node
Updated Function for RuleName
1 parent 57b4a3d commit 3f7c268

File tree

3 files changed

+4
-4
lines changed

3 files changed

+4
-4
lines changed

Functions/New-SysmonCreateRemoteThreadFilter.ps1

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ function New-SysmonCreateRemoteThreadFilter {
7474
if($RuleName) {
7575
$cmdoptions.Add('RuleName',$RuleName)
7676
}
77-
77+
7878
switch($psCmdlet.ParameterSetName) {
7979
'Path' {
8080
$cmdOptions.Add('Path',$Path)

Functions/New-SysmonPipeFilter.ps1

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ function New-SysmonPipeFilter {
8181
if($RuleName) {
8282
$cmdoptions.Add('RuleName',$RuleName)
8383
}
84-
84+
8585
switch ($PSCmdlet.ParameterSetName) {
8686
'Path' {
8787
$cmdOptions.Add('Path',$Path)

Posh-SysMon.psm1

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -257,9 +257,9 @@ function New-RuleFilter
257257
} # If only one element this will return null, more than one this will provide a value.
258258
else
259259
{
260-
if ($RuleData.count -eq $null)
260+
if ($RuleData.count -eq 1)
261261
{
262-
if ($RuleData.onmatch -eq $OnMatch)
262+
if ($RuleData.Attributes."#text" -eq $OnMatch)
263263
{
264264
Write-Verbose -Message 'Single node.'
265265
Write-Verbose -Message "Creating filters for event type $($EventType)."

0 commit comments

Comments
 (0)