Hello, We have a large number of dashboards and queries in our Splunk instance, and some of those are meant for monitoring security-relevant events that never really occur. I'm working toward setting up a service/executable to send WinEVT codes for each event we monitor via a test account. This would allow us to confirm that we are indeed successfully monitoring for events, and aren't missing anything. Currently, I'm failing to get the list of event IDs to write on a Windows host. Is ther another method I could use to ingest a list of event IDs into Splunk to prove our dashboards/queries are working correctly? I realize I could go and physically perform each of the monitored activities, but that would take forever and a day. Thanks in advance for any help!
... View more