Splunk Search

What would be the syntax to search for registry key creation?

Barty001
Engager

What would be the syntax to search for registry key creation?

Tags (1)
0 Karma

jeffland
SplunkTrust
SplunkTrust

You need to explicitly enable auditing for the key you want to watch (google windows registry auditing); after that, you will see events in your windows event log (which you will need to forward to your splunk instance). If I am not mistaken, those would be events with the id 4657, so a search could look something like this:
index = wineventlog | 4657

0 Karma

chimell
Motivator

Hi Barty001
which creation ? please let me known

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...