Getting Data In

Can HKLM\SYSTEM be monitored with Registry Monitoring

kholleran
Communicator

Can someone confirm they are monitoring some keys under here?

I am trying to monitor the USB & USBSTOR keys for any changes (new USB keys plugged in) but it does not send it back to the aggregator. I am monitoring some software keys and they report just fine but the USB's do not....

Thanks.

Kevin

0 Karma

kholleran
Communicator

OK, though my Splunk case a formal bug has been submitted.

0 Karma

kholleran
Communicator

Found it in the web interface under a different heading. Set it up in the web as well, still not passing data.

0 Karma

kholleran
Communicator

OK, so when I click through the registry monitory in the web interface, I get to HKLM\System\CurrentControlSet\Enum & there is nothing there? There should be a whole bunch of stuff but the only key there is PCI? Where is USBSTOR & USB?

Any thoughts? Thanks!

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...