From b0e21a51a5457ce410c77dac688c30a0690eddda Mon Sep 17 00:00:00 2001 From: Yevhenii Basarab Date: Fri, 9 Oct 2026 20:28:04 +0200 Subject: [PATCH] fix(schema): document Windows event-log filters --- specs/windows/windows_eventlog.table | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/specs/windows/windows_eventlog.table b/specs/windows/windows_eventlog.table index f436f26f276..74be6fe4b76 100644 --- a/specs/windows/windows_eventlog.table +++ b/specs/windows/windows_eventlog.table @@ -13,12 +13,25 @@ schema([ Column("data", TEXT, "Data associated with the event"), Column("pid", INTEGER, "Process ID which emitted the event record", additional=True), Column("tid", INTEGER, "Thread ID which emitted the event record"), - Column("time_range", TEXT, "System time to selectively filter the events", hidden=True, additional=True), - Column("timestamp", TEXT, "Timestamp to selectively filter the events", hidden=True, additional=True), - Column("xpath", TEXT, "The custom query to filter events", hidden=True, required=True), + Column("time_range", TEXT, + "UTC event-time filter: start;end ISO 8601 timestamps separated by a semicolon, not a slash. " + "Use a Z suffix; both bounds are inclusive. A single timestamp sets only the lower bound. " + "Requires channel and takes precedence over timestamp.", hidden=True, additional=True), + Column("timestamp", TEXT, + "Maximum event age in milliseconds relative to the device's current time. " + "For example, 10800000 means the last 3 hours. Requires channel; ignored when time_range is set.", + hidden=True, additional=True), + Column("xpath", TEXT, + "Custom Windows Event Log query as QueryList XML containing Query/Select with a Select Path " + "that names the channel. A raw XPath selector is not sufficient. Use xpath alone; " + "it cannot be combined with channel, time_range or timestamp.", hidden=True, required=True), ]) implementation("system/windows_eventlog@genWindowsEventLog", generator=True) examples([ "select * from windows_eventlog where eventid=4625 and channel='Security'", + "select datetime, level, eventid from windows_eventlog where channel='System' and level in (2,3) " + "and time_range='2026-10-01T00:00:00.000Z;2026-10-03T00:00:00.000Z'", + "select datetime, level, eventid from windows_eventlog where channel='System' and level in (2,3) " + "and timestamp='10800000'", ])