Splunk Enterprise Security

How to set up a custom search/alert to track when Windows event log service start/stop for Windows Server 2008+?

metalgear138
Engager

Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012

With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.

0 Karma

Bselberg
Explorer

6005 & 6006 - Applies to 2012,R2, 2016,2019.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee
0 Karma

metalgear138
Engager

Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100

There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)

0 Karma

metalgear138
Engager

Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...