Getting Data In

Monitor .Exe files

AaronMoorcroft
Communicator

Hey Guys,

is there a quick and easy way to monitor .exe within the Windows sys32 folder via a stanza ?

I need to know if the file is ran / closed / renamed or moved

I tried the [monitor] stanza but it looks like that only monitors the file contents i.e. file edits

Thank you

0 Karma

renjith_nair
Legend

Probably the security events might help you

Reference : http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/MonitorfilesystemchangesonWindows

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

AaronMoorcroft
Communicator

Thank you i'll take a look at this option. 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...