Splunk Enterprise Security

How to set up a custom search/alert to track when Windows event log service start/stop for Windows Server 2008+?

metalgear138
Engager

Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012

With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.

0 Karma

Bselberg
Explorer

6005 & 6006 - Applies to 2012,R2, 2016,2019.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee
0 Karma

metalgear138
Engager

Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100

There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)

0 Karma

metalgear138
Engager

Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...