{
  "Name": "Windows Forwarded Events",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The Windows Forwarded Events solution allows you to ingest all [Windows Event Forwarding](https://docs.microsoft.com/advanced-threat-analytics/configure-event-collection) (WEF) logs from the Windows Servers connected to your Microsoft Sentinel workspace using Azure Monitor Agent (AMA).\n\n**Underlying Microsoft Technologies used:**\n\nThis solution is dependent on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\na. [Agent based logs collection from Windows and Linux machines](https://docs.microsoft.com/azure/azure-monitor/agents/data-sources-custom-logs)",
  "Data Connectors": [
    "Data Connectors/WindowsForwardedEvents.json"
  ],
  "Analytic Rules": [
    "Analytic Rules/ChiaCryptoMining_WindowsEvent.yaml",
    "Analytic Rules/CaramelTsunami_IOC_WindowsEvent.yaml",
    "Analytic Rules/moveit_file_transfer_above_threshold.yaml",
    "Analytic Rules/moveit_file_transfer_folders_above_threshold.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\Solutions\\Windows Forwarded Events",
  "Version": "3.0.1",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "StaticDataConnectorIds": [
    "WindowsForwardedEvents"
  ]
}