<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to monitor Microsoft CA logs on Server 2008 R2? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161726#M32803</link>
    <description>&lt;P&gt;What was the solution?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Dec 2017 20:32:54 GMT</pubDate>
    <dc:creator>jlemoine</dc:creator>
    <dc:date>2017-12-11T20:32:54Z</dc:date>
    <item>
      <title>How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161722#M32799</link>
      <description>&lt;P&gt;Has anyone been successful in monitoring Microsoft CA logs on Server 2008 R2?  It looks as if they are being written to C:\Windows\System32\CertLog in EDB log format, which is not human readable.  I want to say the EDB log format might also be used by Microsoft Exchange, so I don't know if any TA or SA for exchange could be leveraged.&lt;/P&gt;

&lt;P&gt;Any assistance with this issue would be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 15:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161722#M32799</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-07-29T15:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161723#M32800</link>
      <description>&lt;P&gt;early morning bump.  No one is monitoring any Microsoft CA servers running on 2008 R2 with Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 13:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161723#M32800</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-07-30T13:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161724#M32801</link>
      <description>&lt;P&gt;Figured out the issue.  There was an additional auditing setting that needed to be tweaked in the GPO before the CA events started showing up in the WinEventLog:Security.  No need to try and figure out a way to monitor the edb files.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 19:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161724#M32801</guid>
      <dc:creator>jodros</dc:creator>
      <dc:date>2014-07-30T19:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161725#M32802</link>
      <description>&lt;P&gt;Do you remember what change did you make in GPO in order to collect CerLog like EventCode=64 etc?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 06:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161725#M32802</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2016-08-09T06:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161726#M32803</link>
      <description>&lt;P&gt;What was the solution?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 20:32:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161726#M32803</guid>
      <dc:creator>jlemoine</dc:creator>
      <dc:date>2017-12-11T20:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor Microsoft CA logs on Server 2008 R2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161727#M32804</link>
      <description>&lt;P&gt;would be helpful, if you could provide how did you fix this.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 07:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-Microsoft-CA-logs-on-Server-2008-R2/m-p/161727#M32804</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-03-24T07:27:58Z</dc:date>
    </item>
  </channel>
</rss>

