Splunk Search

How to view host disk encryption status

dfiore42
New Member

I need a query to view disk encryption (DAR) of all my hosts, be it Bit Locker, LUKS, etc.

index=* host=* | ???

Thank you in advance.

Labels (1)
Tags (3)
0 Karma

ragedsparrow
Contributor

Do you have data in splunk that denotes that the disk in encrypted?  There are a few things to know here:

  • Where your data is stored (index)
  • What differentiates your data  (sourcetype, source, etc)
  • Is your data that you need being monitored? 

Specifically for BitLocker, those are included in Windows Events.  This answer may be helpful in finding where they are: https://community.splunk.com/t5/Getting-Data-In/Retrieving-Windows-Event-logs-with-hyphens-in-the-na... 


0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...