Microsoft Windows

Monitor Windows data with the Splunk platform

How to get Windows data into your Splunk deployment

Windows data you can collect
Link to supporting documentation

Powershell

Monitor Windows data with PowerShell scripts

How to Use PowerShell Transcription Logs in Splunk

[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
renderXml = false
index = wineventlog
source = Microsoft-Windows-PowerShell/Operational
sourcetype = WinEventLog
evt_resolve_ad_obj = 1
[WinEventLog://Windows PowerShell]
disabled = 0
index=wineventlog

Microsoft Defender XDR

Splunk

[WinEventLog://Microsoft-Windows-Windows Defender/Operational]
disabled = 0
renderXml = false
index = wineventlog
source = Microsoft-Windows-Windows Defender/Operational
sourcetype = WinEventLog
evt_resolve_ad_obj = 1

Last updated