Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Collect PSADT and Sysmon Logs #4

Open
wants to merge 6 commits into
base: 1.0
Choose a base branch
from

Conversation

ITsVeritas
Copy link

@ITsVeritas ITsVeritas commented Nov 13, 2023

Pull all *.log files from C:\Windows\Logs\Software, which is the default location that PSADT stores log files.
Collect Sysmon event logs.
Add parameter to allow you to specify which logs to collect or leave it to collect everything selected in the default switch option.

@ITsVeritas ITsVeritas changed the title Add option to collect PSAppDeployToolkit logs Collect PSADT and Sysmon Logs Nov 13, 2023
@ITsVeritas ITsVeritas marked this pull request as draft November 14, 2023 20:55
@ITsVeritas ITsVeritas marked this pull request as ready for review November 20, 2023 18:34
CertSubjectName parsing only worked when the dn was used for the Subject. Modified it to work in cases where the FQDN is used for the cert subject.
Added parameter to specify log location. This adds some flexibility for the person running the script from the ConfigMgr console to specify the log location and simplifies the configuration process since there's nothing to set manually on the Status Filter Rule.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant