There's a default rule for this, look for "Windows Event Log Cleared". It has exactly the logic that ssei posted above.
↧
There's a default rule for this, look for "Windows Event Log Cleared". It has exactly the logic that ssei posted above.