I don’t have any idea on constructing pipeline rules, can any one help me to construct a rule to drop the log if it has EventID:4656 and the filed ProcessName has “C:\Windows\System32\svchost.exe”.
Full Message:
A handle to an object was requested.
Subject:
Security ID: S-1-5-18
Account Name: intelli$
Account Domain: intelli
Logon ID: 0x3e7
Object:
Object Server: PlugPlayManager
Object Type: Security
Object Name: PlugPlaySecurityObject
Handle ID: 0x0
Process Information:
Process ID: 0x328
Process Name: C:\Windows\System32\svchost.exe
Access Request Information:
Transaction ID: {00000000-0000-0000-0000-000000000000}
Accesses: Unknown specific access (bit 1)
Access Reasons: -
Access Mask: 0x2
Privileges Used for Access Check: -
Restricted SID Count: 0
This will be a great help.
Thank you
Ashwath Kumar R