Getting Data In

How to monitor mmc certificates snap-in?

chimbudp
Contributor

how to set the inputs.conf in UF to monitor Certificates Snap-in via mmc ?
Windows

0 Karma

bjoernjensen
Contributor

Hi!

Even though this question is old I ran into the same thing today. Here is what I have found so far:

In the Windows Events you will find changes on the keystore of Windows here:

Event Viewer > Applications and Services Logs > Microsoft > Windows > CertificateServicesClient-Lifecycle-System
Event Viewer > Applications and Services Logs > Microsoft > Windows > CertificateServicesClient-Lifecycle-User

I will be picking both branches. Within those you find if a certificate has been added or removed, etc.

All the best,
Björn

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...