All Apps and Add-ons

Can I add my owen IDs to Eventid.Net

wyomoose
Engager

I am looking for a App that I can take and taylor to a list of eventids that we want to Audit. We like the Eventid.net app but the list of IDs is pretty limited. I would like to take that and maybe just add more IDs to the lookup table or somehow taylor it for us. Any suggestions would be appreciated.

Tags (1)
0 Karma

wyomoose
Engager

Thanks for the reply and stay safe over there. Yep we have the events we want to monitor. I was referring to the Eventid.net apps lookup table called" eventid_interesting_events" I was hoping I could add what we wanted to it and maybe tweak a couple other files and make it work. Sounds like it might just be easier to make our own.

0 Karma

gcusello
Esteemed Legend

Hi @wyomoose,
are you speaking of Microsoft EventCodes?
if yes, see at https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/ or in another similar site found on Google.

Otherwise find your list in internet and create your own EventId lookup; I have many lookups ready for my custom applications.
This is the best approacch so you can create the lookups as you like.

Ciao.
Giuseppe

0 Karma

gcusello
Esteemed Legend

Hi @wyomoose,
if you have a lookup, you can modify it using Lookup Editor, respecting the information and rules used in this lookup:

  • event_id,
  • source,
  • description

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...