Jan 27 2020 12:01 PM
Hi everyone,
do you know any tool or way how to handle PowerShell transcripts like Splunk or HELK?
Would be nice to know how many of you also uses transcripts :)
Regards
Jan 30 2020 04:50 AM - edited Jan 30 2020 04:51 AM
Transcript is not a good idea in combination with Splunk or Elastic Search, because it simply echos whatever was send to the console; whatever ends up in splunk will not be very coherent & make sense. The recommended way of combining powershell & logging is to use scriptblock logging.