{
    "Event": {
        "xmlns": "http://schemas.microsoft.com/win/2004/08/events/event",
        "System": {
            "Provider": {
                "Name": "Microsoft-Windows-Security-Auditing",
                "Guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}"
            },
            "EventID": "4701",
            "Version": "1",
            "Level": "0",
            "Task": "12804",
            "Opcode": "0",
            "Keywords": "0x8020000000000000",
            "TimeCreated": {
                "SystemTime": "2022-07-22T11:09:49.4343573Z"
            },
            "EventRecordID": "220530754",
            "Correlation": {
                "ActivityID": "{a2228185-96ed-0002-4f82-22a2ed96d801}"
            },
            "Execution": {
                "ProcessID": "904",
                "ThreadID": "7404"
            },
            "Channel": "Security",
            "Computer": "someuser.somedomain.ru",
            "Security": null
        },
        "EventData": {
            "Data": [
                {
                    "text": "S-1-5-20",
                    "Name": "SubjectUserSid"
                },
                {
                    "text": "SOMEUSER$",
                    "Name": "SubjectUserName"
                },
                {
                    "text": "SOMEDOMAIN",
                    "Name": "SubjectDomainName"
                },
                {
                    "text": "0x3e4",
                    "Name": "SubjectLogonId"
                },
                {
                    "text": "\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTaskNetwork",
                    "Name": "TaskName"
                },
                {
                    "text": "<?xml version=\"1.0\" encoding=\"UTF-16\"?>\r\n<Task xmlns=\"http://schemas.microsoft.com/windows/2004/02/mit/task\">\r\n  <RegistrationInfo>\r\n    <Version>1.0</Version>\r\n    <SecurityDescriptor>D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-87-431836887-2321537645-4075769387-3393595759-2187231311)</SecurityDescriptor>\r\n    <Source>$(@%systemroot%\\system32\\sppc.dll,-200)</Source>\r\n    <Author>$(@%systemroot%\\system32\\sppc.dll,-200)</Author>\r\n    <Description>$(@%systemroot%\\system32\\sppc.dll,-203)</Description>\r\n    <URI>\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTaskNetwork</URI>\r\n  </RegistrationInfo>\r\n  <Principals>\r\n    <Principal id=\"NetworkService\">\r\n      <UserId>S-1-5-20</UserId>\r\n    </Principal>\r\n  </Principals>\r\n  <Settings>\r\n    <AllowHardTerminate>false</AllowHardTerminate>\r\n    <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>\r\n    <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>\r\n    <Enabled>false</Enabled>\r\n    <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>\r\n    <Hidden>true</Hidden>\r\n    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>\r\n    <RestartOnFailure>\r\n      <Count>3</Count>\r\n      <Interval>PT1M</Interval>\r\n    </RestartOnFailure>\r\n    <IdleSettings>\r\n      <StopOnIdleEnd>true</StopOnIdleEnd>\r\n      <RestartOnIdle>false</RestartOnIdle>\r\n    </IdleSettings>\r\n    <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine>\r\n  </Settings>\r\n  <Triggers>\r\n    <EventTrigger>\r\n      <Subscription>&lt;QueryList&gt;&lt;Query Id=\"0\" Path=\"Microsoft-Windows-NetworkProfile/Operational\"&gt;&lt;Select Path=\"Microsoft-Windows-NetworkProfile/Operational\"&gt;*[System[EventID=10000]]&lt;/Select&gt;&lt;/Query&gt;&lt;/QueryList&gt;</Subscription>\r\n    </EventTrigger>\r\n  </Triggers>\r\n  <Actions Context=\"NetworkService\">\r\n    <ComHandler>\r\n      <ClassId>{B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}</ClassId>\r\n      <Data><![CDATA[network]]></Data>\r\n    </ComHandler>\r\n  </Actions>\r\n</Task>",
                    "Name": "TaskContent"
                },
                {
                    "text": "12947848928736391",
                    "Name": "ClientProcessStartKey"
                },
                {
                    "text": "6220",
                    "Name": "ClientProcessId"
                },
                {
                    "text": "920",
                    "Name": "ParentProcessId"
                },
                {
                    "text": "0",
                    "Name": "RpcCallClientLocality"
                },
                {
                    "text": "someuser.somedomain.ru",
                    "Name": "FQDN"
                }
            ]
        }
    }
}