$end of line
XmlRegex=%<Providerthe literal text XmlRegex=%<Provider (case sensitive) Negated Character Class[^>]+ +matches at least one character outside the set below:
>the literal > (6210 / 768 / 3E16)
Name=the literal text Name= (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
Microsoft-Windows-Security-Auditingthe literal text Microsoft-Windows-Security-Auditing (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
$end of line
XmlRegex=%<EventID>4688<the literal text XmlRegex=%<EventID>4688< (case sensitive) \/the literal / (4710 / 578 / 2F16)
EventID>% the literal text EventID>% (case sensitive) $end of line
XmlRegex=%<Data Name=the literal text XmlRegex=%<Data Name= (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
NewProcessNamethe literal text NewProcessName (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
>C:the literal text >C: (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
Program Files the literal text Program Files (case sensitive) \(the literal ( (4010 / 508 / 2816)
x86the literal text x86 (case sensitive) \)the literal ) (4110 / 518 / 2916)
\\the literal \ (9210 / 1348 / 5C16)
Taniumthe literal text Tanium (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
Tanium Clientthe literal text Tanium Client (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
TaniumClientthe literal text TaniumClient (case sensitive) \.the literal . (4610 / 568 / 2E16)
exe<the literal text exe< (case sensitive) \/the literal / (4710 / 578 / 2F16)
Data>% the literal text Data>% (case sensitive) $end of line
XmlRegex=%<Data Name=the literal text XmlRegex=%<Data Name= (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
ParentProcessNamethe literal text ParentProcessName (case sensitive) "the literal " (3410 / 428 / 2216)
'the literal ' (3910 / 478 / 2716)
>C:the literal text >C: (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
Program Files the literal text Program Files (case sensitive) \(the literal ( (4010 / 508 / 2816)
x86the literal text x86 (case sensitive) \)the literal ) (4110 / 518 / 2916)
\\the literal \ (9210 / 1348 / 5C16)
Taniumthe literal text Tanium (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
Tanium Clientthe literal text Tanium Client (case sensitive) \\the literal \ (9210 / 1348 / 5C16)
TaniumClientthe literal text TaniumClient (case sensitive) \.the literal . (4610 / 568 / 2E16)
exe<the literal text exe< (case sensitive) \/the literal / (4710 / 578 / 2F16)
Data>%the literal text Data>% (case sensitive) g modifier: global. Finds all matches instead of stopping after the first
m modifier: multiline. Causes ^ and $ to match the start and end of each line, not only the start and end of the string