Splunk Enterprise Security

Monitor Unsuccessful Windows Updates

test_qweqwe
Builder

How to change this search to show Unsuccessful/Failed Windows Updates?
sourcetype=WinEventLog:System EventCode=19 | eval Date=strftime(_time, "%Y/%m/%d") | rex "\WKB(?.\d+)\W" | eval successRatio=mvindex(split(Keywords,","),-1) | stats count by Date , host, package_title, KB , body , successRatio| sort host

0 Karma
1 Solution

elliotproebstel
Champion

I think your field extractions are different from mine, but I'll take a stab here. You definitely have an issue with the rex command, because that's not proper syntax. Give this a shot:

rex field=Message "\WKB(?<KB>\d+)\W"

If you still aren't getting the results you expect, try removing the | stats count... portion of the search and ensure that all of the fields you specify are present: Date, host, package_title, KB, body, and successRatio.

View solution in original post

elliotproebstel
Champion

I think your field extractions are different from mine, but I'll take a stab here. You definitely have an issue with the rex command, because that's not proper syntax. Give this a shot:

rex field=Message "\WKB(?<KB>\d+)\W"

If you still aren't getting the results you expect, try removing the | stats count... portion of the search and ensure that all of the fields you specify are present: Date, host, package_title, KB, body, and successRatio.

test_qweqwe
Builder

index=* (sourcetype="*WinEventLog:System" OR sourcetype="WindowsUpdateLog") (KB*) | stats latest(status) as lastStatus by _time, dest, signature, signature_id | search lastStatus=failure

This working

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...