Getting Data In

Logging windows application usage

beezly
Explorer

Is there a way I can use Splunk to log Windows application usage?

I need to be able to see what applications were launched during a users session.

Tags (2)
0 Karma

farleymike
Explorer

You can enable process tracking via Group Policy (local or domain based).

http://technet.microsoft.com/en-us/library/cc775520(v=ws.10).aspx

Once enabled an event is logged to the Windows Security Event Log when a process is started/terminated. However, be aware that process tracking does generate a lot of events!

beezly
Explorer

Exactly what I needed. Thanks very much.

0 Karma

beezly
Explorer

So far I've discovered that this isn't a standard piece of information that gets copied into the Windows Event Log. At the moment we're thinking that we might need to write a piece of code which will drop that information into the event log.

There's an article at http://www.codeproject.com/Articles/2018/Detecting-Windows-NT-2K-process-execution which explains some of the background of running a callback function each time a process is created or destroyed.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...