<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change auditor collect in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432205#M8326</link>
    <description>&lt;P&gt;I'd check your documentation - apparently there's a SIEM Integration Guide with a section on Integration with Splunk.&lt;/P&gt;

&lt;P&gt;I'd need a login at the change auditor site in order to see the details (which you should have if you own the software), but the little that I see when I search their KBase tells me mostly what we need to know.&lt;/P&gt;

&lt;P&gt;When searched for siem, &lt;A href="https://support.quest.com/change-auditor/kb?k=siem"&gt;https://support.quest.com/change-auditor/kb?k=siem&lt;/A&gt;, shows a couple of tidbits:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... to write Change Auditor audited events locally to a Windows event log.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And also &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Select the subsystems to include in the subscription. Click Finish. For more information please see the "Managing a Splunk integration" section of the SIEM Integration Guide.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When you put those two together, I believe Change Auditor can record events into the Windows Event Log, and from there you can either collect them into Splunk via UF or WMI, or can use Event Log Forwarding (an MS thing) to move those logs to another system, from where you can collect them via UF or WMI.&lt;/P&gt;

&lt;P&gt;But either way, that SIEM guide should get you started!&lt;/P&gt;

&lt;P&gt;Happy Splunking!&lt;BR /&gt;
-Rich&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 12:45:07 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2018-07-11T12:45:07Z</dc:date>
    <item>
      <title>Change auditor collect</title>
      <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432202#M8323</link>
      <description>&lt;P&gt;hello every body ,&lt;/P&gt;

&lt;P&gt;someone know how to configure splunk for collect  change auditor logs please ?&lt;/P&gt;

&lt;P&gt;Thansk in advance&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432202#M8323</guid>
      <dc:creator>ALLIACOM</dc:creator>
      <dc:date>2018-07-11T12:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Change auditor collect</title>
      <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432203#M8324</link>
      <description>&lt;P&gt;Hi Alliacom,&lt;/P&gt;

&lt;P&gt;Pls refer the below link for more information, let me know if it works for you.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.4/Security/AuditSplunkactivity"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.4/Security/AuditSplunkactivity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432203#M8324</guid>
      <dc:creator>manish_singh_77</dc:creator>
      <dc:date>2018-07-11T12:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Change auditor collect</title>
      <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432204#M8325</link>
      <description>&lt;P&gt;Hi manish thank's for you answer but &lt;BR /&gt;
i'm talking about dell change auditor  logs and not splunk audit logs&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:31:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432204#M8325</guid>
      <dc:creator>ALLIACOM</dc:creator>
      <dc:date>2018-07-11T12:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Change auditor collect</title>
      <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432205#M8326</link>
      <description>&lt;P&gt;I'd check your documentation - apparently there's a SIEM Integration Guide with a section on Integration with Splunk.&lt;/P&gt;

&lt;P&gt;I'd need a login at the change auditor site in order to see the details (which you should have if you own the software), but the little that I see when I search their KBase tells me mostly what we need to know.&lt;/P&gt;

&lt;P&gt;When searched for siem, &lt;A href="https://support.quest.com/change-auditor/kb?k=siem"&gt;https://support.quest.com/change-auditor/kb?k=siem&lt;/A&gt;, shows a couple of tidbits:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... to write Change Auditor audited events locally to a Windows event log.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And also &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Select the subsystems to include in the subscription. Click Finish. For more information please see the "Managing a Splunk integration" section of the SIEM Integration Guide.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When you put those two together, I believe Change Auditor can record events into the Windows Event Log, and from there you can either collect them into Splunk via UF or WMI, or can use Event Log Forwarding (an MS thing) to move those logs to another system, from where you can collect them via UF or WMI.&lt;/P&gt;

&lt;P&gt;But either way, that SIEM guide should get you started!&lt;/P&gt;

&lt;P&gt;Happy Splunking!&lt;BR /&gt;
-Rich&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432205#M8326</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-07-11T12:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Change auditor collect</title>
      <link>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432206#M8327</link>
      <description>&lt;P&gt;Oh I see....&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 12:52:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Change-auditor-collect/m-p/432206#M8327</guid>
      <dc:creator>manish_singh_77</dc:creator>
      <dc:date>2018-07-11T12:52:14Z</dc:date>
    </item>
  </channel>
</rss>

