diff --git a/Crowdstrike/200850-crowdstrike.xml b/Crowdstrike/200850-crowdstrike.xml index ff30197..6d9cce5 100644 --- a/Crowdstrike/200850-crowdstrike.xml +++ b/Crowdstrike/200850-crowdstrike.xml @@ -1,6 +1,7 @@ \.+ + no_full_log CrowdStrike Alert - $(event.OperationName) @@ -16,6 +17,7 @@ 200850 \.+ + no_full_log CrowdStrike Alert - $(event.DetectDescription)