diff --git a/evtx/Maps/System_Microsoft-Windows-GroupPolicy_1130.map b/evtx/Maps/System_Microsoft-Windows-GroupPolicy_1130.map new file mode 100644 index 00000000..db1c90d9 --- /dev/null +++ b/evtx/Maps/System_Microsoft-Windows-GroupPolicy_1130.map @@ -0,0 +1,75 @@ +Author: Chris Kudless chris.kudless@gmail.com +Description: Group Policy Script Failure +EventId: 1130 +Channel: System +Provider: Microsoft-Windows-GroupPolicy +Maps: + - + Property: PayloadData1 + PropertyValue: "Command String: %GPOScriptCommandString%" + Values: + - + Name: GPOScriptCommandString + Value: "/Event/EventData/Data[@Name=\"GPOScriptCommandString\"]" + - + Property: PayloadData2 + PropertyValue: "Error: %ErrorDescription%" + Values: + - + Name: ErrorDescription + Value: "/Event/EventData/Data[@Name=\"ErrorDescription\"]" + - + Property: PayloadData3 + PropertyValue: "GPO: %GPODisplayName%" + Values: + - + Name: GPODisplayName + Value: "/Event/EventData/Data[@Name=\"GPODisplayName\"]" + - + Property: PayloadData4 + PropertyValue: "GPO Path: %GPOFileSystemPath%" + Values: + - + Name: GPOFileSystemPath + Value: "/Event/EventData/Data[@Name=\"GPOFileSystemPath\"]" + - + Property: PayloadData5 + PropertyValue: "Error Code: %ErrorCode%" + Values: + - + Name: ErrorCode + Value: "/Event/EventData/Data[@Name=\"ErrorCode\"]" + +# Documentation: +# https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc727309(v=ws.10)?redirectedfrom=MSDN +# https://kb.eventtracker.com/evtpass/evtpages/EventId_1130_Microsoft-Windows-GroupPolicy_64357.asp +# +# Example Event Data: +#Event> +# +# +# 1130 +# 0 +# 2 +# 0 +# 0 +# 0x8000000000000000 +# +# 71924 +# +# +# System +# HOST1.company.corp +# +# +# +# 0 +# 0 +# 2 +# The system cannot find the file specified. +# 0 +# Default Domain Policy +# \\COMPANY.corp\sysvol\COMPANY.corp\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine +# badness.bat +# +#/Event>