New Application Installation
Configuration
query
EventID:903 OR EventID:904 AND NOT SourceName:Directory Synchronization AND NOT SourceName:InstalledADSyncPowerShellHelper AND NOT SourceName:Azure AD Connect Upgrade AND NOT SourceName:MicrosoftAzureActiveDirectoryClient AND NOT SourceName:Microsoft\-Windows\-Application\-Experience
config
Key | Value — | — type | aggregation-v1 query | EventID:903 OR EventID:904 AND NOT SourceName:Directory Synchronization AND NOT SourceName:InstalledADSyncPowerShellHelper AND NOT SourceName:Azure AD Connect Upgrade AND NOT SourceName:MicrosoftAzureActiveDirectoryClient AND NOT SourceName:Microsoft\-Windows\-Application\-Experience streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000
Windows Software and Service Installation
As part of normal network operations, new software and services will be installed, and there is value in monitoring this activity.