Splunk Enterprise Security

tag=registry

VijaySrrie
Builder

Hi,

I am forwarding sysmon logs to splunk, for normalization, I could see event ID : 12, 13, 14 are captured (Registry object added or deleted, Registry value added, Registry value modified)

All are success events, will there be any failure events under the above mentioned eventIDs?

Labels (2)
0 Karma
1 Solution

VijaySrrie
Builder

There wont be any failure events for endpoint datamodel  and tag=registry, tested it with the non-admin account.

Only success events (registry keys/values  - modified/renamed/created new, deleted) are captured under eventviewer

 

View solution in original post

0 Karma

VijaySrrie
Builder

There wont be any failure events for endpoint datamodel  and tag=registry, tested it with the non-admin account.

Only success events (registry keys/values  - modified/renamed/created new, deleted) are captured under eventviewer

 

0 Karma
Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...