diff --git a/data_sources/windows_event_log_security_1102.yml b/data_sources/windows_event_log_security_1102.yml index b254610771..0f893ef485 100644 --- a/data_sources/windows_event_log_security_1102.yml +++ b/data_sources/windows_event_log_security_1102.yml @@ -1,7 +1,7 @@ name: Windows Event Log Security 1102 id: 8db7b91a-6d7a-40e7-bfac-06f8e901a9cb -version: 3 -date: '2025-07-10' +version: 4 +date: '2026-04-15' author: Patrick Bareiss, Splunk description: Logs an event when the audit log is cleared. mitre_components: @@ -85,18 +85,12 @@ fields: - vendor_product output_fields: - action -- app - change_type - dest - dvc -- name -- object_attrs - object_category -- signature - signature_id -- src_user - status -- subject - user - vendor_product example_log: