All Apps and Add-ons

Why is the TA_Windows 5 breaks Splunk Security Essentials?

skenigma
Engager

Splunk_TA_Windows renames the sourcetypes for the windows logs.
WinEventLog:Security for example is renamed to wineventlog

Security Essentials searches fail.

| metasearch earliest=-2h latest=now sourcetype="*WinEventLog:Security" index=* | head 100 | stats count 

Is this planned on being fixed, or should I remove Splunk_TA_Windows to use Security Essentials?

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Ah ha! Thank you for the detailed question! I wasn't aware of this.

Yes, I'm nearing complete on SSE 2.2, and will have this fixed in that version. I'll post back here once I release it, but expect it no more than 2 weeks away, and I'll strive to have it done within 1 week.

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

Ah ha! Thank you for the detailed question! I wasn't aware of this.

Yes, I'm nearing complete on SSE 2.2, and will have this fixed in that version. I'll post back here once I release it, but expect it no more than 2 weeks away, and I'll strive to have it done within 1 week.

0 Karma

skenigma
Engager

Thank you for your response. I look forward to working with the new version and verifying the data.

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...