<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to utilize Splunk Enterprise to perform automated audits on Windows event logs on a standalone environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-utilize-Splunk-Enterprise-to-perform-automated-audits-on/m-p/279404#M53494</link>
    <description>&lt;P&gt;You should take the time first to run through the Splunk tutorial here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchTutorial/WelcometotheSearchTutorial"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt; This will give you some familiarity with how splunk works and how to get data into it. &lt;/P&gt;

&lt;P&gt;In terms of how to achieve your audit that is really going to depend on what you need audited! If you're just getting a list of logins for two PCs I would probably suggest Splunk is overkill. Instead you can just connect to the event viewer on each PC and run a search. &lt;/P&gt;

&lt;P&gt;If you do want to go down the Splunk route have a look at this prebuilt collection of inputs and dashboards:  &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/4.8.1/User/AbouttheSplunkAdd-onforWindows"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/4.8.1/User/AbouttheSplunkAdd-onforWindows&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2016 18:18:58 GMT</pubDate>
    <dc:creator>jplumsdaine22</dc:creator>
    <dc:date>2016-02-15T18:18:58Z</dc:date>
    <item>
      <title>How to utilize Splunk Enterprise to perform automated audits on Windows event logs on a standalone environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-utilize-Splunk-Enterprise-to-perform-automated-audits-on/m-p/279403#M53493</link>
      <description>&lt;P&gt;Trying to use Splunk Enterprise as a tool to perform automated auditing of my event logs.  I have a couple standalone PCs and am required to perform bi-weekly audits.  Would love to be able to have this process automated.  &lt;/P&gt;

&lt;P&gt;Does anyone have "laymen" instructions on how to accomplish this task?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 13:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-utilize-Splunk-Enterprise-to-perform-automated-audits-on/m-p/279403#M53493</guid>
      <dc:creator>mrglover</dc:creator>
      <dc:date>2016-02-11T13:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to utilize Splunk Enterprise to perform automated audits on Windows event logs on a standalone environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-utilize-Splunk-Enterprise-to-perform-automated-audits-on/m-p/279404#M53494</link>
      <description>&lt;P&gt;You should take the time first to run through the Splunk tutorial here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchTutorial/WelcometotheSearchTutorial"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt; This will give you some familiarity with how splunk works and how to get data into it. &lt;/P&gt;

&lt;P&gt;In terms of how to achieve your audit that is really going to depend on what you need audited! If you're just getting a list of logins for two PCs I would probably suggest Splunk is overkill. Instead you can just connect to the event viewer on each PC and run a search. &lt;/P&gt;

&lt;P&gt;If you do want to go down the Splunk route have a look at this prebuilt collection of inputs and dashboards:  &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/4.8.1/User/AbouttheSplunkAdd-onforWindows"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/4.8.1/User/AbouttheSplunkAdd-onforWindows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 18:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-utilize-Splunk-Enterprise-to-perform-automated-audits-on/m-p/279404#M53494</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-02-15T18:18:58Z</dc:date>
    </item>
  </channel>
</rss>

