Installation

Windows Unified Write Filter (UWF) Exclusions for Splunk Universal Forwarders-What file and registry path is required?

johnhuang
Motivator

What file and registry path is required for Windows Splunk Universal Forwarder?

Looking to deploy Unified Write Filter (UWF) to harden kiosks/shared Windows workstations. UWF works by redirecting all non-approved file and registry write to temporary memory which is wiped out by a reboot.

We need to identify the file and registry locations which Splunk Universal Forwarder (UF) requires so it can be excluded from UWF. 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...