Splunk Enterprise

How To Know WinLogs Stanza Per Event ID

morethanyell
Builder

Hi,

I got a request to onboard Event IDs 3039, 3040, 3041, 2886, 2887, 2888, 2889. I tried to Google them but couldn't see anything that will tell which logsource they're from.

I don't know if I should put them under System i.e.

 

 

[WinEventLog://System]
index = winlogs_of_domain_controllers
whitelist = 2886-2889,3039-3041

 

 

Or Security i.e.

 

[WinEventLog://Security]
index = winlogs_of_domain_controllers
whitelist = 2886-2889,3039-3041

 

 

I was hoping someone could point me to a trusty website?

 

Thank you.

Labels (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

Ask the person who requested those to be ingested.

Event IDs can be duplicated for different purposes across many different event logs, so a System 3039 may exist, and a Security 3039 may exist, and they may be completely different types of events.  You absolutely have to know which event 3039 they want you to ingest.

Happy Splunking

-Rich

0 Karma

morethanyell
Builder

Understood. I never thought that Event Codes can have duplicates in System and Security. Thanks a bunch.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...