Splunk Enterprise Security

windows server monitoring

punithjigali
Explorer

Hi team,

I have used windows add on to get events from server to my splunk instance using universal fowarder.

I want some of the monitoring examples that has bean already implemented so that I will go through that, get to practice and apply...

please share some of the example links...

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @punithjigali,
if you see in punithjigali Enterprise Security [Configure -- Content -- Content Management] you can enable or disable Use Cases.
At [Configure -- Content -- Libraries] you can see a description of the Use Cases.

In addition, if you install the Splunk Security Essentials ( https://splunkbase.splunk.com/app/3435/ ), there's an interesting feature that analyze your data and says what use Cases are toggled.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...