mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-07-03 11:13:50 +00:00
@ -1,21 +0,0 @@
|
|||||||
<ViewerConfig>
|
|
||||||
<QueryConfig>
|
|
||||||
<QueryParams>
|
|
||||||
<Simple>
|
|
||||||
<Channel>Microsoft-Windows-Windows Defender/Operational,Microsoft-Windows-Windows Defender/WHC</Channel>
|
|
||||||
<EventId>1</EventId>
|
|
||||||
<RelativeTimeInfo>0</RelativeTimeInfo>
|
|
||||||
<BySource>False</BySource>
|
|
||||||
</Simple>
|
|
||||||
</QueryParams>
|
|
||||||
<QueryNode>
|
|
||||||
<Name>Test view</Name>
|
|
||||||
<QueryList>
|
|
||||||
<Query Id="0" Path="Microsoft-Windows-Windows Defender/Operational">
|
|
||||||
<Select Path="Microsoft-Windows-Windows Defender/Operational">*[System[(EventID=1)]]</Select>
|
|
||||||
<Select Path="Microsoft-Windows-Windows Defender/WHC">*[System[(EventID=1)]]</Select>
|
|
||||||
</Query>
|
|
||||||
</QueryList>
|
|
||||||
</QueryNode>
|
|
||||||
</QueryConfig>
|
|
||||||
</ViewerConfig>
|
|
Reference in New Issue
Block a user