I have loaded the module for EVTX analysis and I get two results:
Windows Event Logs
Windows Event Logs Long Tail Analysis
How are the items in the long tail analysis determined? Is it just a count of EventIDs? I want to make sure I understand it.
This is a great module - Thanks!!
Bob