All Apps and Add-ons

How to extract version information from event viewer logs for Windows Defender?

dreha
New Member

Can someone help me with setting up a search that could pull version information from a Windows Defender event 1151 log?

I have the TA for Windows Defender app installed and I believe that the data is being parsed correctly. I am fairly new in getting started with Splunk and have been unable to determine what type of search syntax does what I want it to do.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...