Getting Data In

Unable to index Windows registry monitoring (Certain Registry values)

santosh_scb
Path Finder

Hi

I have a requirement where I need to monitor certain registry key values on Windows server 2016. I am using the below configs in inputs.conf for monitoring but unable to index the data and also dont see any results in search.

Tried following the Splunk doc as well but couldnt get much help. 

Let me know if you have come across any such issues and rectified it. 

Contents of inputs.conf

[WinRegMon://HKLM]
baseline=1
disabled=0
hive=\\REGISTRY\\SYSTEM\\*ControlSet*\\Services\\LanManServer\\Shares\\?.*

hive=\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit
hive=\\HKEY_LOCAL_MACHINE\\SYSTEM\\*ControlSet*\\Services\\LanmanServer\\Parameters\\autodisconnect
index=windows
proc=.*
source=WinRegistry
type=set|create|delete|rename|query

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...