One aspect of security configuration I don't see talked about enough is verbosity vs retention.
Do you really want this event of marginal use if it makes you have 20 fewer days before logs turnover?
@SwiftOnSecurity “the CrowdStrike story”