Update windows/security/information-protection/windows-information-protection/collect-wip-audit-event-logs.md

Meryljoyce Ypil

Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
This commit is contained in:
ImranHabib 2019-05-27 23:16:38 +05:00 committed by GitHub
parent 1a1b94ff36
commit 7d18ae3a36
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -169,7 +169,7 @@ You can collect audit logs using Azure Monitor. See [Windows event log data sour
**To view the WIP events in Azure Monitor** **To view the WIP events in Azure Monitor**
1. Use an existing or create a new Log Analytics workspace. 1. Use an existing or create a new Log Analytics workspace.
2. In Log Analytics->Advanced Settings, go to Data, in Windows Event Logs, add logs to receive: 2. In **Log Analytics** > **Advanced Settings**, select **Data**. In Windows Event Logs, add logs to receive:
``` ```
Microsoft-Windows-EDP-Application-Learning/Admin Microsoft-Windows-EDP-Application-Learning/Admin
Microsoft-Windows-EDP-Audit-TCB/Admin Microsoft-Windows-EDP-Audit-TCB/Admin