Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: AppLocker Logs in LEM

$
0
0

Alright, so this took some fiddling with ProcMon, but I think I have an answer.  You'll need to test it, though.

 

ProcMon got me to this part of the Windows Registry:

 

 

And you can see the "File" key has the path.  Since it's in the registry, should be easy enough to set a GPO to set that on machines or use PowerShell to adjust it.  I went and played in my lab domain for a bit and came up with this, which I believe makes all the required changes (see attached).


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>