Getting Data In

Unable to index Windows registry monitoring (Certain Registry values)

santosh_scb
Path Finder

Hi

I have a requirement where I need to monitor certain registry key values on Windows server 2016. I am using the below configs in inputs.conf for monitoring but unable to index the data and also dont see any results in search.

Tried following the Splunk doc as well but couldnt get much help. 

Let me know if you have come across any such issues and rectified it. 

Contents of inputs.conf

[WinRegMon://HKLM]
baseline=1
disabled=0
hive=\\REGISTRY\\SYSTEM\\*ControlSet*\\Services\\LanManServer\\Shares\\?.*

hive=\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\?.*
hive=\\HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit
hive=\\HKEY_LOCAL_MACHINE\\SYSTEM\\*ControlSet*\\Services\\LanmanServer\\Parameters\\autodisconnect
index=windows
proc=.*
source=WinRegistry
type=set|create|delete|rename|query

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...