<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to monitor  HKLM\\SYSTEM\\CurrentControlSet\\Enum\\USBSTOR  but nothing is happening in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-monitor-HKLM-SYSTEM-CurrentControlSet-Enum-USBSTOR-but/m-p/98756#M182632</link>
    <description>&lt;P&gt;The following set up was used in regmon-filters.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinRegistry]
proc = C:\\.*
baseline = 0
disabled = 0
hive = HKLM\\SYSTEM\\CurrentControlSet\\Enum\\USBSTOR\\?.*
index = default
type = rename|close|set|delete|open|create|query
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When adding a USB drive, I see nothing being reported on.  What is going on?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2013 17:02:53 GMT</pubDate>
    <dc:creator>bosburn_splunk</dc:creator>
    <dc:date>2013-01-24T17:02:53Z</dc:date>
    <item>
      <title>Trying to monitor  HKLM\\SYSTEM\\CurrentControlSet\\Enum\\USBSTOR  but nothing is happening</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-monitor-HKLM-SYSTEM-CurrentControlSet-Enum-USBSTOR-but/m-p/98756#M182632</link>
      <description>&lt;P&gt;The following set up was used in regmon-filters.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinRegistry]
proc = C:\\.*
baseline = 0
disabled = 0
hive = HKLM\\SYSTEM\\CurrentControlSet\\Enum\\USBSTOR\\?.*
index = default
type = rename|close|set|delete|open|create|query
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When adding a USB drive, I see nothing being reported on.  What is going on?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2013 17:02:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-monitor-HKLM-SYSTEM-CurrentControlSet-Enum-USBSTOR-but/m-p/98756#M182632</guid>
      <dc:creator>bosburn_splunk</dc:creator>
      <dc:date>2013-01-24T17:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to monitor  HKLM\\SYSTEM\\CurrentControlSet\\Enum\\USBSTOR  but nothing is happening</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-monitor-HKLM-SYSTEM-CurrentControlSet-Enum-USBSTOR-but/m-p/98757#M182633</link>
      <description>&lt;P&gt;This is a known issue - SPL-58682 - with Splunk monitoring the Current Control Set for this section.  The work around is to use the following setting for hive:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hive = HKEY_LOCAL_MACHINE\\SYSTEM\\*CONTROLSET*\\ENUM\\USBSTOR?.*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will monitor all control sets for changes for that path.&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2013 17:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-monitor-HKLM-SYSTEM-CurrentControlSet-Enum-USBSTOR-but/m-p/98757#M182633</guid>
      <dc:creator>bosburn_splunk</dc:creator>
      <dc:date>2013-01-24T17:04:57Z</dc:date>
    </item>
  </channel>
</rss>

