Getting Data In

Windows_TA vs Windows

cachexploit
Explorer

I have two apps installed on Windows clients.  One looks like the full blown Windows_TA app and one looks like a truncated one.  I worked with a PS to get all these apps initially installed. 

Everything in the full Win_TA looks to be disabled.

The truncated one looks very simple and has some stanzas from the Win_TA app.

I made a change to the truncated one (a blacklist addition) and I believe this has taken.

Am I assuming correctly that the one app that has a truncated version of Windows TA is the actual app that is telling what logs for the Win hosts to send?

Also, if my assumption are correct, is this common practice?

Labels (1)
Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

you need an input to collect windows events logs that input can be added to any application name. it's not required to be in specific application name. The application name is required for you to understand what kind of inputs the application contains.

you can have one application for example:

windows_inputs and create local directory inside that and create inputs.conf inside that and add your input stanzas. its very simple. 

let me know if you still need some guidance.

————————————
If this helps, give a like below.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...