Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 16 additions & 3 deletions specs/windows/windows_eventlog.table
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,25 @@ schema([
Column("data", TEXT, "Data associated with the event"),
Column("pid", INTEGER, "Process ID which emitted the event record", additional=True),
Column("tid", INTEGER, "Thread ID which emitted the event record"),
Column("time_range", TEXT, "System time to selectively filter the events", hidden=True, additional=True),
Column("timestamp", TEXT, "Timestamp to selectively filter the events", hidden=True, additional=True),
Column("xpath", TEXT, "The custom query to filter events", hidden=True, required=True),
Column("time_range", TEXT,
"UTC event-time filter: start;end ISO 8601 timestamps separated by a semicolon, not a slash. "
"Use a Z suffix; both bounds are inclusive. A single timestamp sets only the lower bound. "
"Requires channel and takes precedence over timestamp.", hidden=True, additional=True),
Column("timestamp", TEXT,
"Maximum event age in milliseconds relative to the device's current time. "
"For example, 10800000 means the last 3 hours. Requires channel; ignored when time_range is set.",
hidden=True, additional=True),
Column("xpath", TEXT,
"Custom Windows Event Log query as QueryList XML containing Query/Select with a Select Path "
"that names the channel. A raw XPath selector is not sufficient. Use xpath alone; "
"it cannot be combined with channel, time_range or timestamp.", hidden=True, required=True),
])

implementation("system/windows_eventlog@genWindowsEventLog", generator=True)
examples([
"select * from windows_eventlog where eventid=4625 and channel='Security'",
"select datetime, level, eventid from windows_eventlog where channel='System' and level in (2,3) "
"and time_range='2026-10-01T00:00:00.000Z;2026-10-03T00:00:00.000Z'",
"select datetime, level, eventid from windows_eventlog where channel='System' and level in (2,3) "
"and timestamp='10800000'",
])
Loading