Monitoring Splunk

Monitor SCCM Log & correlate to file system changes

kholleran
Communicator

Hi,

Currently we monitor some systems with the filesystem change. Almost all the time, any triggers to this are from our updates pushed by the SCCM server. I'd like to start monitoring the systems for when patches are applied by SCCM and correlate that with the filesystem changes via some searches to quickly rule these out as malicious behavior.

How can I monitor SCCM applying updates?

Thanks.

Kevin

Tags (2)

carasso
Splunk Employee
Splunk Employee

We're hosting a contest for the best SCCM app.

http://splunk.challengepost.com/

Microsoft SCCM - The first place winner in the Microsoft SCCM app category wins $30,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference. Value: approx. $1,695.

Innovation - The first place winner in the Innovation category wins $20,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference.

0 Karma

dart
Splunk Employee
Splunk Employee

Does this reference of SCCM log files help?

0 Karma

kholleran
Communicator

Does anyone monitor SCCM logs with Splunk? I know you can do the windows update.log file but what about SCCM? Have I stumped everyone?

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...