cmdReporter Wiki

Open navigation

PREFERENCE_LIST_EVENT

{
  "_event_score": 0,
  "event_attributes": {
    "AuditEventExcludedProcesses": [
      "/usr/bin/log",
      "/usr/sbin/syslogd"
    ],
    "AuditEventExcludedUsers": [
      "_spotlight",
      "_windowserver"
    ],
    "AuditEventLogVerboseMessages": 1,
    "AuditLevel": 3,
    "FileEventExclusionPaths": [
      "/Users/.*/Library/.*"
    ],
    "FileEventInclusionPaths": [
      "/Users/.*"
    ],
    "FileEventUseFuzzyMatch": 0,
    "FileLicenseInfo": {
      "LicenseEmail": "dan@cmdsec.com",
      "LicenseExpirationDate": "01/01/2020",
      "LicenseKey": "43cafc3da47e792939ea82c70958103720e21d0662e3a97416f96b30d11a5ab8bdcfa5cf50a42079c3f33c36cd1618e2865b54275fd3c1698521ba1a9c228e2122d62fa521aeec930b9d0c2aa8c16891895726e2619d3a781f3155731ed9917cff7b5e270c7abdd1b2a655786e0bf00cd1292de262979d92ce26c4d65a8b33eefdbe5984802825f83b4622563fd708c4256843b2f5e2fd93f83566f8b95021c4a4d72ac83165545ff45e76efd23ffc2b1bbb1a3fde2eb683d05866437d2b6d4b",
      "LicenseType": "Annual",
      "LicenseVersion": "1"
    },
    "LogFileLocation": "/var/log/cmdReporter.log",
    "LogFileMaxNumberBackups": 10,
    "LogFileMaxSizeMegaBytes": 10,
    "LogFileOwnership": "root:wheel",
    "LogFilePermission": "640",
    "LogRemoteEndpointEnabled": 1,
    "LogRemoteEndpointType": "AWSKinesis",
    "LogRemoteEndpointTypeAWSKinesis": {
      "AccessKeyId": "AKIAQFENLIMPJSPK37XX",
      "Region": "us-east-1",
      "SecretKey": "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",
      "StreamName": "cmdReporter_testing"
    },
    "LogRemoteEndpointURL": "",
    "UnifiedLogPredicates": [
      "'(subsystem == \"com.example.networkstatistics\")'",
      "'(subsystem == \"com.apple.CryptoTokenKit\" AND category == \"AHP\")'"
    ],
    "Version": "3.1b43"
  },
  "header": {
    "event_name": "PREFERENCE_LIST_EVENT",
    "time_seconds_epoch": 1570033028
  },
  "host_info": {
    "host_name": "Dan_macbook_pro",
    "host_uuid": "3F6E4B3A-9285-4E7E-9A0C-C3B62DC379DF",
    "osversion": "Version 10.14.6 (Build 18G95)",
    "primary_mac_address": "38:f9:e8:15:5a:82",
    "serial_number": "C03XY889JHG3"
  }
}


Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.