Monitoring Splunk

Monitor SCCM Log & correlate to file system changes

kholleran
Communicator

Hi,

Currently we monitor some systems with the filesystem change. Almost all the time, any triggers to this are from our updates pushed by the SCCM server. I'd like to start monitoring the systems for when patches are applied by SCCM and correlate that with the filesystem changes via some searches to quickly rule these out as malicious behavior.

How can I monitor SCCM applying updates?

Thanks.

Kevin

Tags (2)

carasso
Splunk Employee
Splunk Employee

We're hosting a contest for the best SCCM app.

http://splunk.challengepost.com/

Microsoft SCCM - The first place winner in the Microsoft SCCM app category wins $30,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference. Value: approx. $1,695.

Innovation - The first place winner in the Innovation category wins $20,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference.

0 Karma

dart
Splunk Employee
Splunk Employee

Does this reference of SCCM log files help?

0 Karma

kholleran
Communicator

Does anyone monitor SCCM logs with Splunk? I know you can do the windows update.log file but what about SCCM? Have I stumped everyone?

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...