Alerting

Is it possible to create an alert in Splunk Enterprise if a command is run in CMD?

rodiers01
New Member

Is it possible in Splunk Enterprise to create an alert if someone were to run a command in MS-DOS?

Specifically I'm looking to create an alert if this command below is run in CMD

auditpol /clear /y

This is something a malicious actor would do so that auditing is turned off on the machine and then they can go about their business.

Thanks for any input

0 Karma

wenthold
Communicator

I believe you want to enable command line logging in Windows.

MS Docs on command line logging

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...