<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Events in Security</title>
    <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443184#M13251</link>
    <description>&lt;P&gt;As nickhill mentioned, if you could add more details, that would great.&lt;/P&gt;

&lt;P&gt;I am assuming,  you want to understand the Windows Audit polices and then enable required 'Windows event codes' which can then be monitored using Splunk TA.&lt;/P&gt;

&lt;P&gt;I suggest, you discuss with your Windows AD admin, who manages Domain controller and endpoints policies [ e.g. enable audit to log account logons - that produce 4624 event code]. Then using &lt;A href="https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/monitoring-active-directory-for-signs-of-compromise"&gt;https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/monitoring-active-directory-for-signs-of-compromise&lt;/A&gt;, you can enable/validate policies to match your need.&lt;/P&gt;

&lt;P&gt;Once the Windows event codes are available, you can install Splunk TA for windows or Splunk TA for Active directory and onboard them events to splunk &lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2019 15:49:41 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-03-18T15:49:41Z</dc:date>
    <item>
      <title>Security Events</title>
      <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443182#M13249</link>
      <description>&lt;P&gt;Anyone help me on below,&lt;/P&gt;

&lt;P&gt;1) Login&lt;BR /&gt;
2) Logoff&lt;BR /&gt;
3) Un-successful login&lt;BR /&gt;
4) Modify authentication mechanisms&lt;BR /&gt;
5) Create user account&lt;BR /&gt;
6) Modify user account&lt;BR /&gt;
7) Create role&lt;BR /&gt;
8) Modify role&lt;BR /&gt;
9) Grant/revoke user privileges&lt;BR /&gt;
10) Grant/revoke role privileges&lt;BR /&gt;
11) Privileged commands&lt;BR /&gt;
12) Modify audit and logging&lt;BR /&gt;
13) Objects Create/Modify/Delete&lt;BR /&gt;
14) Modify configuration settings&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 12:31:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-Events/m-p/443182#M13249</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2019-03-18T12:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security Events</title>
      <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443183#M13250</link>
      <description>&lt;P&gt;I think you need to provide a bit more context. For example, What is the source of these logs, do you have the relevant TA's loaded, do you have the Authentication and Change CIM datamodels configured etc.?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 12:58:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-Events/m-p/443183#M13250</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-18T12:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Events</title>
      <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443184#M13251</link>
      <description>&lt;P&gt;As nickhill mentioned, if you could add more details, that would great.&lt;/P&gt;

&lt;P&gt;I am assuming,  you want to understand the Windows Audit polices and then enable required 'Windows event codes' which can then be monitored using Splunk TA.&lt;/P&gt;

&lt;P&gt;I suggest, you discuss with your Windows AD admin, who manages Domain controller and endpoints policies [ e.g. enable audit to log account logons - that produce 4624 event code]. Then using &lt;A href="https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/monitoring-active-directory-for-signs-of-compromise"&gt;https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/monitoring-active-directory-for-signs-of-compromise&lt;/A&gt;, you can enable/validate policies to match your need.&lt;/P&gt;

&lt;P&gt;Once the Windows event codes are available, you can install Splunk TA for windows or Splunk TA for Active directory and onboard them events to splunk &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 15:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-Events/m-p/443184#M13251</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-18T15:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security Events</title>
      <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443185#M13252</link>
      <description>&lt;P&gt;Thank you for the reply. I am new to the splunk, could you please share us is there any document or how to check is Splunk TA installed for Windows. &lt;/P&gt;

&lt;P&gt;The above reports need to configure for WIndows machines. Please suggest me what is starting point. &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 18:30:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-Events/m-p/443185#M13252</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2019-03-18T18:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Events</title>
      <link>https://community.splunk.com/t5/Security/Security-Events/m-p/443186#M13253</link>
      <description>&lt;P&gt;Thank you for the reply. I am new to the splunk, could you please share us is there any document or how to check is Splunk TA installed for Windows. &lt;/P&gt;

&lt;P&gt;The above reports need to configure for WIndows machines. Please suggest me what is starting point. &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 18:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-Events/m-p/443186#M13253</guid>
      <dc:creator>brpsingara</dc:creator>
      <dc:date>2019-03-18T18:30:51Z</dc:date>
    </item>
  </channel>
</rss>

