Monitoring Splunk

How can I monitor if someone is using wireless keyboard or mouse ?

Aizo
New Member

Hi,

 

Is there any way to control if users are using wireless keyboard or mouse ? 

 

 

Labels (1)
0 Karma

Aizo
New Member

Hello @tej57 

Thank you for your answer.

I forgot to mention that bluetooth is deactivated in BIOS. Using wireless keyboard and mouse is forbidden and I'm wondering how to monitor that users won't connect their wireless devices by dongle USB . (  I can't deactivate USB ports ) 

0 Karma

tej57
Communicator

For Windows devices, you can enable Security, Application eventlogs using Splunk Add-on for Microsoft Windows. Event Code - 6416 contains the logs whenever an external device connects to the Windows machine. 

For Linux devices, you can monitor the messages directory which contains all the activity information. And then based on the logs, you can setup an alert to get triggered for a specific regex pattern.

0 Karma

tej57
Communicator

Hello @Aizo,

The wireless keyboard and mouse would be connected to a device using the Bluetooth preferences. If you could monitor the processes or the connectivity logs for a device, you can get the information if the device is connected to a bluetooth mouse/keyboard or not.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...