Splunk Enterprise Security

How to set up a custom search/alert to track when Windows event log service start/stop for Windows Server 2008+?

metalgear138
Engager

Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012

With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.

0 Karma

Bselberg
Explorer

6005 & 6006 - Applies to 2012,R2, 2016,2019.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee
0 Karma

metalgear138
Engager

Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100

There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)

0 Karma

metalgear138
Engager

Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...