Deployment Architecture

Picking which logs to monitor

mmcap
Explorer

When monitoring Windows systems which logs do you find to give the best information for finding security events and then tracking down the event from start to finish?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap ,

uing the Splunk Ta Windows (https://splunkbase.splunk.com/app/742) you can monitor many things on a windows devoce (server or cliente).

If you have security requisites, the first data source should be wineventlog:security.

But there are many other sources that could be interesting.

As I said, open the Add-On and see the possible inputs you have so you can choose the one you could require.

Ciao.

Giuseppe

mmcap
Explorer

Hi Giuseppe,

I appreciate the lightning fast answer and I agree, there is a multitude of  logs to choose from. That's kind of the problem. 

I will most certainly look at the link you supplied but I was trying to find out which logs other people feel work best for them. 

In the mean time I will have a look around the content on your link.

Ciao

Norm 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap,

as I said, you can start from the wineventlog:security logs that contain the most information useful for security, then you could take processes, to identify if there's some rogue process, open ports and local admins.

I usually enable all the logs, eventually disabling only the performace monitoring because it's very verbose and (for this reason) expensive (in terms of license).

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is Splunk's InfoSec app, which you can look and thing what are those panels which are important to you. Based on that you can check which logs are needed to fulfil those.

https://splunkbase.splunk.com/app/4240

Very easy to setup and use, but still you will get lot of information what is happening.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...