<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Windows Registry in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482295#M82659</link>
    <description>&lt;P&gt;Hi Adonio I am using the TA for Windows and I also followed the doc, however my events still do not look like the ones you have in the screen shot. This is the monitor I am using, not sure if it aligns with the one you are using.&lt;/P&gt;

&lt;P&gt;[WinRegMon://hklm_run]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
hive = \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.*&lt;BR /&gt;
proc = .*&lt;BR /&gt;
index = windows&lt;BR /&gt;
type = rename|set|create|delete|rename&lt;/P&gt;

&lt;P&gt;Also, do you think I need to make any changes or configs to any other file? In order to get all the other events to come in properly?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2019 12:17:36 GMT</pubDate>
    <dc:creator>cald0002</dc:creator>
    <dc:date>2019-11-13T12:17:36Z</dc:date>
    <item>
      <title>Configuring Windows Registry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482293#M82657</link>
      <description>&lt;P&gt;I am having trouble extracting certain information from registry events. For example I want to extract  the "SetValue" from the registry type, however, when I try to use the "extract fields" option to create to create a field for it, Splunk does not allow me to select that specific string to create the field. Is there a way to fix this? Or an alternative method to create fields for registry_type and also key_path and process_image?&lt;/P&gt;

&lt;P&gt;event_status="(0)The operation completed successfully."&lt;BR /&gt;
pid=7008&lt;BR /&gt;
process_image="svchost.exe"&lt;BR /&gt;
registry_type="SetValue"&lt;BR /&gt;
key_path="HKU\s-1-5-20\software\microsoft\windows\currentversion\deliveryoptimization\config\downloadmode_backcompat"&lt;BR /&gt;
data_type="REG_DWORD"&lt;BR /&gt;
data="0x00000001(1)"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:56:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482293#M82657</guid>
      <dc:creator>cald0002</dc:creator>
      <dc:date>2020-09-30T02:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Windows Registry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482294#M82658</link>
      <description>&lt;P&gt;are you using the Splunk TA for Windows?&lt;BR /&gt;
did you follow this doc:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/MonitorWindowsregistrydata"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/MonitorWindowsregistrydata&lt;/A&gt;&lt;BR /&gt;
I see all the fields extracted, screenshot below&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7943i8636B7A0764F4B32/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 13:58:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482294#M82658</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-11-12T13:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Windows Registry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482295#M82659</link>
      <description>&lt;P&gt;Hi Adonio I am using the TA for Windows and I also followed the doc, however my events still do not look like the ones you have in the screen shot. This is the monitor I am using, not sure if it aligns with the one you are using.&lt;/P&gt;

&lt;P&gt;[WinRegMon://hklm_run]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
hive = \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.*&lt;BR /&gt;
proc = .*&lt;BR /&gt;
index = windows&lt;BR /&gt;
type = rename|set|create|delete|rename&lt;/P&gt;

&lt;P&gt;Also, do you think I need to make any changes or configs to any other file? In order to get all the other events to come in properly?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 12:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482295#M82659</guid>
      <dc:creator>cald0002</dc:creator>
      <dc:date>2019-11-13T12:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Windows Registry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482296#M82660</link>
      <description>&lt;P&gt;I also had an asterisk at the end of hive in proc, not sure why it didnt come up.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 12:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Windows-Registry/m-p/482296#M82660</guid>
      <dc:creator>cald0002</dc:creator>
      <dc:date>2019-11-13T12:18:58Z</dc:date>
    </item>
  </channel>
</rss>

