I am new to SPLUNK. Installed SPLUNK enterprise and have installed splunk forwarder on a workstation. Configured Data forwarder on Indexer to send Application, System and Security logs from the workstation. I want report on CD DVD activity on this client machine, and not sure how to do this. Is there a particular EVENT ID I should be using? I have copied data from DVD to the local machine and back again but cannot find any events. Is there something else I need to setup on the client machine?
Any help on this would be much appreciated.
Thanks for reply and the link to EventTracker .. most useful