Microsoft Windows

Monitor Windows data with the Splunk platformarrow-up-right

How to get Windows data into your Splunk deployment

Powershell

Monitor Windows data with PowerShell scriptsarrow-up-right

How to Use PowerShell Transcription Logs in Splunkarrow-up-right

[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
renderXml = false
index = wineventlog
source = Microsoft-Windows-PowerShell/Operational
sourcetype = WinEventLog
evt_resolve_ad_obj = 1

Microsoft Defender XDR

Splunkarrow-up-right

Last updated