Ingest Windows application event logs

we are trying to ingest windows event id 4103 and 4104 to be able to see powershell commands, but they are not under normal windows events, they fall under applications and services logs/microsoft/windows/poweshell/operational. how do we solve this?

Hi, @kirsteinw: You may find this document helpful: