Getting Data In

Can HKLM\SYSTEM be monitored with Registry Monitoring

kholleran
Communicator

Can someone confirm they are monitoring some keys under here?

I am trying to monitor the USB & USBSTOR keys for any changes (new USB keys plugged in) but it does not send it back to the aggregator. I am monitoring some software keys and they report just fine but the USB's do not....

Thanks.

Kevin

0 Karma

kholleran
Communicator

OK, though my Splunk case a formal bug has been submitted.

0 Karma

kholleran
Communicator

Found it in the web interface under a different heading. Set it up in the web as well, still not passing data.

0 Karma

kholleran
Communicator

OK, so when I click through the registry monitory in the web interface, I get to HKLM\System\CurrentControlSet\Enum & there is nothing there? There should be a whole bunch of stuff but the only key there is PCI? Where is USBSTOR & USB?

Any thoughts? Thanks!

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...