<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HKLM\SYSTEM\CurrentControlSet Monitoring in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407037#M11930</link>
    <description>&lt;P&gt;There is already another post and answer to this question:&lt;/P&gt;

&lt;P&gt;This is a known issue - SPL-58682 - with Splunk monitoring the Current Control Set for this section. The work around is to use the following setting for hive:&lt;BR /&gt;
1. hive = HKEY_LOCAL_MACHINE\SYSTEM\&lt;EM&gt;CONTROLSET&lt;/EM&gt;\ENUM\USBSTOR?.*&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:00:56 GMT</pubDate>
    <dc:creator>nathanhfraenkel</dc:creator>
    <dc:date>2020-09-30T01:00:56Z</dc:date>
    <item>
      <title>HKLM\SYSTEM\CurrentControlSet Monitoring</title>
      <link>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407035#M11928</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I try to monitor the Registry Hive HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters. Unfortunately, it didn’t get any Event from this registry hive.&lt;/P&gt;

&lt;P&gt;I have setup the Monitoring the following way:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinRegMon://hklm_dnsserver]
disabled = 0
hive = HKEY_LOCAL_MACHINE\\SYSTEM\\*ControlSet*\\Services\\DNS\\Parameters\\.*
proc = .*
type = set|create|delete|rename
index = windows
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If already tried a lot of different path defintions like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hive = \\REGISTRY\\MACHINE\\SYSTEM\\*ControlSet*\\Services\\DNS\\Parameters\\.*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hive = \\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\DNS\\Parameters\\.*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hive = \\REGISTRY\\MACHINE\\SYSTEM\\ControlSet001\\Services\\DNS\\Parameters\\.*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;other registry keys, for example, under HKLM\SOFTWARE are working without Problems.&lt;/P&gt;

&lt;P&gt;Did anyone managed to get a working registry Monitoring for HKLM\CurrentControlSet?&lt;/P&gt;

&lt;P&gt;Kind regards&lt;BR /&gt;
Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 13:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407035#M11928</guid>
      <dc:creator>hayduk</dc:creator>
      <dc:date>2018-11-29T13:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: HKLM\SYSTEM\CurrentControlSet Monitoring</title>
      <link>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407036#M11929</link>
      <description>&lt;P&gt;I have the same problem. If I enable ControlSet001 and 002 works fine. As soon as I enable CurrentControlSet all three stop working.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 10:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407036#M11929</guid>
      <dc:creator>nathanhfraenkel</dc:creator>
      <dc:date>2019-06-20T10:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: HKLM\SYSTEM\CurrentControlSet Monitoring</title>
      <link>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407037#M11930</link>
      <description>&lt;P&gt;There is already another post and answer to this question:&lt;/P&gt;

&lt;P&gt;This is a known issue - SPL-58682 - with Splunk monitoring the Current Control Set for this section. The work around is to use the following setting for hive:&lt;BR /&gt;
1. hive = HKEY_LOCAL_MACHINE\SYSTEM\&lt;EM&gt;CONTROLSET&lt;/EM&gt;\ENUM\USBSTOR?.*&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/HKLM-SYSTEM-CurrentControlSet-Monitoring/m-p/407037#M11930</guid>
      <dc:creator>nathanhfraenkel</dc:creator>
      <dc:date>2020-09-30T01:00:56Z</dc:date>
    </item>
  </channel>
</rss>

