Splunk Search

What would be the syntax to search for registry key creation?

Barty001
Engager

What would be the syntax to search for registry key creation?

Tags (1)
0 Karma

jeffland
SplunkTrust
SplunkTrust

You need to explicitly enable auditing for the key you want to watch (google windows registry auditing); after that, you will see events in your windows event log (which you will need to forward to your splunk instance). If I am not mistaken, those would be events with the id 4657, so a search could look something like this:
index = wineventlog | 4657

0 Karma

chimell
Motivator

Hi Barty001
which creation ? please let me known

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...