HOTSPOT
-
You have on-premises servers that run Windows Server.
You have a Microsoft Sentinel workspace named SW1. SW1 is configured to collect Windows Security log entries from the servers by using the Azure Monitor Agent data connector.
You plan to limit the scope of collected events to events 4624 and 4625 only.
You need to use a PowerShell script to validate the syntax of the filter applied to the connector.
How should you complete the script? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
inkedia3
Highly Voted 10 months agobrichardson14
Highly Voted 1 year agoOneplusOne
Most Recent 2 weeks agoOptimizor_IT
2 months agoHAjouz
3 months, 1 week agosmanzana
10 months, 2 weeks agorenrenren
1 year agoVeiN
7 months, 2 weeks ago