Splunk Enterprise Security

How to onboard System32\winevt\Logs\Microsoft-Windows-DNSServer%4Audit.evtx

Rishabh_McKc
Explorer

In my server I want to onboard DNS Audit logs in addition to DNS Events. DNS Audit logs are getting created in
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DNSServer%4Audit.evtx

Could you please help me how can i onbard it

0 Karma

Rishabh_McKc
Explorer

I found the solution.

for getting logs on-boarded from the path: C:\Windows\System32\winevt\Logs\Microsoft-Windows-DNSServer%4Audit.evtx. We need below stanza in inputs.conf on universal forwarder:

[WinEventLog://Microsoft-Windows-DNSServer/Audit]
checkpointInterval = 5
current_only = 0
disabled = 0
index =
start_from = oldest

Add your comment...

vishaltaneja070
Motivator

I think you can monitor the above path, to onboard the logs to splunk

0 Karma

Rishabh_McKc
Explorer

I found the solution.

for getting logs on-boarded from the path: C:\Windows\System32\winevt\Logs\Microsoft-Windows-DNSServer%4Audit.evtx. We need below stanza in inputs.conf on universal forwarder:

[WinEventLog://Microsoft-Windows-DNSServer/Audit]
checkpointInterval = 5
current_only = 0
disabled = 0
index =
start_from = oldest

Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...