evtx_explain_event_id
Get descriptions for Windows Event IDs to understand security events and system activities during forensic investigations.
Instructions
Get description of a Windows Event ID.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| event_id | Yes | ||
| channel | No | Security |