Getting Data In

Monitor .Exe files

AaronMoorcroft
Communicator

Hey Guys,

is there a quick and easy way to monitor .exe within the Windows sys32 folder via a stanza ?

I need to know if the file is ran / closed / renamed or moved

I tried the [monitor] stanza but it looks like that only monitors the file contents i.e. file edits

Thank you

0 Karma

renjith_nair
Legend

Probably the security events might help you

Reference : http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/MonitorfilesystemchangesonWindows

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

AaronMoorcroft
Communicator

Thank you i'll take a look at this option. 🙂

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...