Splunk Enterprise Security

How to set up a custom search/alert to track when Windows event log service start/stop for Windows Server 2008+?

metalgear138
Engager

Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012

With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.

0 Karma

Bselberg
Explorer

6005 & 6006 - Applies to 2012,R2, 2016,2019.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee
0 Karma

metalgear138
Engager

Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100

There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)

0 Karma

metalgear138
Engager

Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...