Getting Data In

Unable to index Windows registry monitoring (Certain Registry values)

santosh_scb
Path Finder

Hi

I have a requirement where I need to monitor certain registry key values on Windows server 2016. I am using the below configs in inputs.conf for monitoring but unable to index the data and also dont see any results in search.

Tried following the Splunk doc as well but couldnt get much help. 

Let me know if you have come across any such issues and rectified it. 

Contents of inputs.conf

[WinRegMon://HKLM]
baseline=1
disabled=0
hive=\\REGISTRY\\SYSTEM\\*ControlSet*\\Services\\LanManServer\\Shares\\?.*

hive=\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit
hive=\\HKEY_LOCAL_MACHINE\\SYSTEM\\*ControlSet*\\Services\\LanmanServer\\Parameters\\autodisconnect
index=windows
proc=.*
source=WinRegistry
type=set|create|delete|rename|query

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...