Monitoring Splunk

Monitor SCCM Log & correlate to file system changes

kholleran
Communicator

Hi,

Currently we monitor some systems with the filesystem change. Almost all the time, any triggers to this are from our updates pushed by the SCCM server. I'd like to start monitoring the systems for when patches are applied by SCCM and correlate that with the filesystem changes via some searches to quickly rule these out as malicious behavior.

How can I monitor SCCM applying updates?

Thanks.

Kevin

Tags (2)

carasso
Splunk Employee
Splunk Employee

We're hosting a contest for the best SCCM app.

http://splunk.challengepost.com/

Microsoft SCCM - The first place winner in the Microsoft SCCM app category wins $30,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference. Value: approx. $1,695.

Innovation - The first place winner in the Innovation category wins $20,000 and a complimentary pass to .conf 2015 - Splunk's premier annual user conference.

0 Karma

dart
Splunk Employee
Splunk Employee

Does this reference of SCCM log files help?

0 Karma

kholleran
Communicator

Does anyone monitor SCCM logs with Splunk? I know you can do the windows update.log file but what about SCCM? Have I stumped everyone?

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...