Monitoring Splunk

Does WinRegMon requires the Windows Remote Registry service?

merdenoms
Loves-to-Learn Everything

I want to keep the Windows Remote Registry service turned off on my Windows machines.  I decided to use Splunk to monitor the service and see if anything turns it on.  It turns out that Splunk is actually turning on and off the service throughout the day.  This is probably because I'm using WinRegMon to monitor the registry.

 

Does Splunk actually require the Remote Registry service?  Or is this something I can disable?  I was wondering why Splunk turns the service on for remote use when the Splunk forwarder is installed locally on the Windows machine.

 

Here is an example of what I have in my inputs.conf:

 

 

[WinRegMon://RegistryMonitor]
baseline = 0
disabled = 0
hive = HKEY_USERS\\.*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
proc = C:\\.*
type = rename|close|set|delete|open|create|query

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...