Reporting

What's the best datamodel to audit processes ran by users? and filesystem changes?

3DGjos
Communicator

Hello Again, I'm developing a compliance app (CIM, with tstats), now is the turn to write a search to monitor processes ran by users on the domain (windows and linux, maybe some other source of interest)

My doubt is, what datamodel should I use? I'm between Endpoint and Change. But endpoint does not have a user field, I don't understand why ¿What would be the right approarch?

For filesystem changes, I personally like Change but the SA-Cim definition, on the constraint part worries me, it litterally says:

(`cim_Change_indexes`) tag=change NOT (object_category=file OR object_category=directory OR object_category=registry)

I could just not parse the events with object_category=file, but I would like to know why is this, I mean, the endpoint datamodel does not have an object_category field, for example. Why I can't use it?

Thanks!

0 Karma
1 Solution

lakshman239
Influencer
0 Karma

lakshman239
Influencer

Pls accept if this helped to resolve your query, to help tracking

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...