Deployment Architecture

Picking which logs to monitor

mmcap
Explorer

When monitoring Windows systems which logs do you find to give the best information for finding security events and then tracking down the event from start to finish?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap ,

uing the Splunk Ta Windows (https://splunkbase.splunk.com/app/742) you can monitor many things on a windows devoce (server or cliente).

If you have security requisites, the first data source should be wineventlog:security.

But there are many other sources that could be interesting.

As I said, open the Add-On and see the possible inputs you have so you can choose the one you could require.

Ciao.

Giuseppe

mmcap
Explorer

Hi Giuseppe,

I appreciate the lightning fast answer and I agree, there is a multitude of  logs to choose from. That's kind of the problem. 

I will most certainly look at the link you supplied but I was trying to find out which logs other people feel work best for them. 

In the mean time I will have a look around the content on your link.

Ciao

Norm 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mmcap,

as I said, you can start from the wineventlog:security logs that contain the most information useful for security, then you could take processes, to identify if there's some rogue process, open ports and local admins.

I usually enable all the logs, eventually disabling only the performace monitoring because it's very verbose and (for this reason) expensive (in terms of license).

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is Splunk's InfoSec app, which you can look and thing what are those panels which are important to you. Based on that you can check which logs are needed to fulfil those.

https://splunkbase.splunk.com/app/4240

Very easy to setup and use, but still you will get lot of information what is happening.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...