<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac OS high sierra USB monitoring in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423236#M5309</link>
    <description>&lt;P&gt;I know that osquery is capable of USB device monitoring and there are a couple of Splunk apps dedicated to osquery monitoring.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3902/"&gt;https://splunkbase.splunk.com/app/3902/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3278/"&gt;https://splunkbase.splunk.com/app/3278/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This would mean installing the osquery client on the endpoints but Macs are supported.&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jul 2018 17:55:15 GMT</pubDate>
    <dc:creator>LukeMurphey</dc:creator>
    <dc:date>2018-07-07T17:55:15Z</dc:date>
    <item>
      <title>Mac OS high sierra USB monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423235#M5308</link>
      <description>&lt;P&gt;Is there a way to Monitor USB activity for all Mac books and systems on an enterprise level? For example maybe use logs to grab the device ID of a USB and forward it to Splunk where Splunk can alert you of such activity.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 21:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423235#M5308</guid>
      <dc:creator>johns0n1216</dc:creator>
      <dc:date>2018-07-06T21:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS high sierra USB monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423236#M5309</link>
      <description>&lt;P&gt;I know that osquery is capable of USB device monitoring and there are a couple of Splunk apps dedicated to osquery monitoring.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3902/"&gt;https://splunkbase.splunk.com/app/3902/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://splunkbase.splunk.com/app/3278/"&gt;https://splunkbase.splunk.com/app/3278/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This would mean installing the osquery client on the endpoints but Macs are supported.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 17:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423236#M5309</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2018-07-07T17:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS high sierra USB monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423237#M5310</link>
      <description>&lt;P&gt;Do you have any documentation for installing these add ons they don't have much info on their page. &lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 15:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Mac-OS-high-sierra-USB-monitoring/m-p/423237#M5310</guid>
      <dc:creator>johns0n1216</dc:creator>
      <dc:date>2018-07-11T15:47:14Z</dc:date>
    </item>
  </channel>
</rss>

