Microsoft-Windows-Sudo

2 events across 1 channel

Event IDTitleChannel
1Admin
2Admin

Event ID 1 —

Provider
Microsoft-Windows-Sudo
Channel
Admin

Message

%8

Fields

NameDescription
Application
ArgsCount
Argument
CurrentWorkingDirectory
Mode
InheritEnvironment
Redirected
FullCommandline
RequestID

Event ID 2 —

Provider
Microsoft-Windows-Sudo
Channel
Admin

Message

%8

Fields

NameDescription
Application
ArgsCount
Argument
CurrentWorkingDirectory
Mode
InheritEnvironment
Redirected
FullCommandline
RequestID