Hello,
Is there any way where we can know what are all applications are accessed by the user instead of just logon/log off activities from the winevent logs? Can someone help me with the search?
Thanks
Splunk can only tell you what it is told by Windows. Are you running sysmon on the Windows devices? If so, then you can get detailed user activity; otherwise, you're limited to what's in the event logs (that have been indexed).
Splunk can only tell you what it is told by Windows. Are you running sysmon on the Windows devices? If so, then you can get detailed user activity; otherwise, you're limited to what's in the event logs (that have been indexed).