All Apps and Add-ons

Can I add my owen IDs to Eventid.Net

wyomoose
Engager

I am looking for a App that I can take and taylor to a list of eventids that we want to Audit. We like the Eventid.net app but the list of IDs is pretty limited. I would like to take that and maybe just add more IDs to the lookup table or somehow taylor it for us. Any suggestions would be appreciated.

Tags (1)
0 Karma

wyomoose
Engager

Thanks for the reply and stay safe over there. Yep we have the events we want to monitor. I was referring to the Eventid.net apps lookup table called" eventid_interesting_events" I was hoping I could add what we wanted to it and maybe tweak a couple other files and make it work. Sounds like it might just be easier to make our own.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wyomoose,
are you speaking of Microsoft EventCodes?
if yes, see at https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/ or in another similar site found on Google.

Otherwise find your list in internet and create your own EventId lookup; I have many lookups ready for my custom applications.
This is the best approacch so you can create the lookups as you like.

Ciao.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wyomoose,
if you have a lookup, you can modify it using Lookup Editor, respecting the information and rules used in this lookup:

  • event_id,
  • source,
  • description

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...