mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
23 lines
1.2 KiB
YAML
23 lines
1.2 KiB
YAML
name: Previously Seen Running Windows Services - Initial
|
|
id: 64ce0ade-cb01-4678-bddd-d31c0b175394
|
|
version: 5
|
|
creation_date: '2020-04-29'
|
|
modification_date: '2026-05-13'
|
|
author: David Dorsey, Splunk
|
|
status: production
|
|
description: This collects the services that have been started across your entire enterprise.
|
|
search: '`wineventlog_system` EventCode=7036 | rex field=Message "The (?<service>[-\(\)\s\w]+) service entered the (?<state>\w+) state" | where state="running" | stats earliest(_time) as firstTimeSeen, latest(_time) as lastTimeSeen by service | outputlookup previously_seen_running_windows_services'
|
|
how_to_implement: While this search does not require you to adhere to Splunk CIM, you must be ingesting your Windows security-event logs for it to execute successfully. Please ensure that the Splunk Add-on for Microsoft Windows is version 8.0.0 or above.
|
|
known_false_positives: No false positives have been identified at this time.
|
|
references: []
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
security_domain: endpoint
|
|
custom_schedule:
|
|
cron_schedule: 0 2 * * 0
|
|
earliest_time: -90d@d
|
|
latest_time: -1d@d
|
|
schedule_window: auto
|