Security

Security Events

brpsingara
Explorer

Anyone help me on below,

1) Login
2) Logoff
3) Un-successful login
4) Modify authentication mechanisms
5) Create user account
6) Modify user account
7) Create role
8) Modify role
9) Grant/revoke user privileges
10) Grant/revoke role privileges
11) Privileged commands
12) Modify audit and logging
13) Objects Create/Modify/Delete
14) Modify configuration settings

Thanks in advance.

Tags (1)
0 Karma

lakshman239
Influencer

As nickhill mentioned, if you could add more details, that would great.

I am assuming, you want to understand the Windows Audit polices and then enable required 'Windows event codes' which can then be monitored using Splunk TA.

I suggest, you discuss with your Windows AD admin, who manages Domain controller and endpoints policies [ e.g. enable audit to log account logons - that produce 4624 event code]. Then using https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/monitori..., you can enable/validate policies to match your need.

Once the Windows event codes are available, you can install Splunk TA for windows or Splunk TA for Active directory and onboard them events to splunk

0 Karma

brpsingara
Explorer

Thank you for the reply. I am new to the splunk, could you please share us is there any document or how to check is Splunk TA installed for Windows.

The above reports need to configure for WIndows machines. Please suggest me what is starting point.

0 Karma

nickhills
Ultra Champion

I think you need to provide a bit more context. For example, What is the source of these logs, do you have the relevant TA's loaded, do you have the Authentication and Change CIM datamodels configured etc.?

If my comment helps, please give it a thumbs up!
0 Karma

brpsingara
Explorer

Thank you for the reply. I am new to the splunk, could you please share us is there any document or how to check is Splunk TA installed for Windows.

The above reports need to configure for WIndows machines. Please suggest me what is starting point.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...