Installation

Windows Unified Write Filter (UWF) Exclusions for Splunk Universal Forwarders-What file and registry path is required?

johnhuang
Motivator

What file and registry path is required for Windows Splunk Universal Forwarder?

Looking to deploy Unified Write Filter (UWF) to harden kiosks/shared Windows workstations. UWF works by redirecting all non-approved file and registry write to temporary memory which is wiped out by a reboot.

We need to identify the file and registry locations which Splunk Universal Forwarder (UF) requires so it can be excluded from UWF. 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...