<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring Registry via universal forwarder not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Registry-via-universal-forwarder-not-working/m-p/482853#M82726</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am trying to monitor a registry key from a remote server using a universal forwarder. No matter what i put in my inputs.conf, i just cannot get it to work. This is my inputs.conf:&lt;/P&gt;

&lt;P&gt;[WinRegMon://Registry]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
hive = HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SOPHOS\AUTOUPDATE\UPDATESTATUS\.*&lt;BR /&gt;
proc = .*&lt;BR /&gt;
type = set&lt;/P&gt;

&lt;P&gt;I can see the following error in my splunkd.log:&lt;/P&gt;

&lt;P&gt;message from ""Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "Program Files\SplunkUniversalForwarder\bin""  splunk-regmon - No enabled entries have been found for regmon or procmon in the conf file.&lt;/P&gt;

&lt;P&gt;I must be missing something simple! Please help!&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:12:52 GMT</pubDate>
    <dc:creator>evo1988</dc:creator>
    <dc:date>2020-09-30T02:12:52Z</dc:date>
    <item>
      <title>Monitoring Registry via universal forwarder not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Registry-via-universal-forwarder-not-working/m-p/482853#M82726</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am trying to monitor a registry key from a remote server using a universal forwarder. No matter what i put in my inputs.conf, i just cannot get it to work. This is my inputs.conf:&lt;/P&gt;

&lt;P&gt;[WinRegMon://Registry]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
hive = HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SOPHOS\AUTOUPDATE\UPDATESTATUS\.*&lt;BR /&gt;
proc = .*&lt;BR /&gt;
type = set&lt;/P&gt;

&lt;P&gt;I can see the following error in my splunkd.log:&lt;/P&gt;

&lt;P&gt;message from ""Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "Program Files\SplunkUniversalForwarder\bin""  splunk-regmon - No enabled entries have been found for regmon or procmon in the conf file.&lt;/P&gt;

&lt;P&gt;I must be missing something simple! Please help!&lt;/P&gt;

&lt;P&gt;Many thanks,&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:12:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Registry-via-universal-forwarder-not-working/m-p/482853#M82726</guid>
      <dc:creator>evo1988</dc:creator>
      <dc:date>2020-09-30T02:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Registry via universal forwarder not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Registry-via-universal-forwarder-not-working/m-p/482854#M82727</link>
      <description>&lt;P&gt;From inputs.conf:&lt;BR /&gt;
  If you configure the inputs with Splunk Web, the value of "" matches&lt;BR /&gt;
  what was specified there. While you can add event log monitor inputs&lt;BR /&gt;
  manually, it is best practice to use Splunk Web to configure&lt;BR /&gt;
  Windows registry monitor inputs because it is easy to mistype the values&lt;BR /&gt;
  for Registry hives and keys.&lt;/P&gt;

&lt;P&gt;Have you tried installing Splunk on a box that has sophos installed, and drilling down into that particular registry key as an input and then seeing what it wrote for the actual stanza?  &lt;/P&gt;

&lt;P&gt;Here's what I get using some other random key... maybe it'll help you spot anything wrong with your own.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinRegMon://MyTest]
baseline = 0
disabled = 0
hive = HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Mozilla\\NativeMessagingHosts\\com.webex.meeting
index = bugger_all
proc = C:\\.*
type = set
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also please use the code button to paste code so that the special characters don't get eaten by the editor.&lt;/P&gt;

&lt;P&gt;Lastly, I'd not name the stanza "registry".  If you want another key later, ... well, then you either have two stanzas named "registry" and "registry2" (lol) or you'll have one named "registry" and another "typicalSpywareKeys", which ... the "registry" one seems a bit out of place then.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 00:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Registry-via-universal-forwarder-not-working/m-p/482854#M82727</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2019-09-26T00:50:58Z</dc:date>
    </item>
  </channel>
</rss>

