Deployment Architecture

Picking which logs to monitor

mmcap
Explorer

When monitoring Windows systems which logs do you find to give the best information for finding security events and then tracking down the event from start to finish?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap ,

uing the Splunk Ta Windows (https://splunkbase.splunk.com/app/742) you can monitor many things on a windows devoce (server or cliente).

If you have security requisites, the first data source should be wineventlog:security.

But there are many other sources that could be interesting.

As I said, open the Add-On and see the possible inputs you have so you can choose the one you could require.

Ciao.

Giuseppe

mmcap
Explorer

Hi Giuseppe,

I appreciate the lightning fast answer and I agree, there is a multitude of  logs to choose from. That's kind of the problem. 

I will most certainly look at the link you supplied but I was trying to find out which logs other people feel work best for them. 

In the mean time I will have a look around the content on your link.

Ciao

Norm 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap,

as I said, you can start from the wineventlog:security logs that contain the most information useful for security, then you could take processes, to identify if there's some rogue process, open ports and local admins.

I usually enable all the logs, eventually disabling only the performace monitoring because it's very verbose and (for this reason) expensive (in terms of license).

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is Splunk's InfoSec app, which you can look and thing what are those panels which are important to you. Based on that you can check which logs are needed to fulfil those.

https://splunkbase.splunk.com/app/4240

Very easy to setup and use, but still you will get lot of information what is happening.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...