Dear All,
how can I know that if someone uninstall anti virus solution on windows server or client. can we get that logs with windows TA ?
Greetings @riqbal47010,
Yes, this is possible with the Windows TA. See documentation below. Of particular interest to you is WinEventLog in the third link. You can also check out the inputs.conf
in the default
directory after installing the add-on (note that all inputs are disabled by default - you can copy stanzas into a new inputs.conf
in the local
directory in order to enable Event Log monitoring). 11724
is the Windows Application Event Code that documents uninstallations.
https://splunkbase.splunk.com/app/742/#/details
https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration
Greetings @riqbal47010,
Yes, this is possible with the Windows TA. See documentation below. Of particular interest to you is WinEventLog in the third link. You can also check out the inputs.conf
in the default
directory after installing the add-on (note that all inputs are disabled by default - you can copy stanzas into a new inputs.conf
in the local
directory in order to enable Event Log monitoring). 11724
is the Windows Application Event Code that documents uninstallations.
https://splunkbase.splunk.com/app/742/#/details
https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/AbouttheSplunkAdd-onforWindows
https://docs.splunk.com/Documentation/WindowsAddOn/6.0.0/User/Configuration