Files
splunk-security_content/baselines/monitor_successful_windows_updates.json
2019-03-27 11:13:11 -04:00

45 lines
1.4 KiB
JSON

{
"channel": "ESCU",
"creation_date": "2017-08-24",
"data_metadata": {
"data_models": [
"Updates"
],
"data_source": [
"Windows Updates"
],
"providing_technologies": [
"Microsoft Windows"
]
},
"eli5": "This search gives you the count and name of all the systems that had a successful update applied each day",
"how_to_implement": "You must be ingesting your Windows Update Logs",
"maintainers": [
{
"company": "Splunk",
"email": "davidd@splunk.com",
"name": "David Dorsey"
}
],
"modification_date": "2017-09-14",
"original_authors": [
{
"company": "Splunk",
"email": "davidd@splunk.com",
"name": "David Dorsey"
}
],
"scheduling": {
"earliest_time": "-30d@d",
"latest_time": "-10m@m"
},
"search": "| tstats `summariesonly` dc(Updates.dest) as count FROM datamodel=Updates where Updates.vendor_product=\"Microsoft Windows\" AND Updates.status=installed by _time span=1d",
"search_description": "This search is intended to give you a feel for how often successful Windows updates are applied in your environments. Fluctuations in these numbers will allow you to determine when you should be concerned.",
"search_id": "6a80535c-86a6-4b54-894c-4b446d0c701d",
"search_name": "Windows Updates Install Successes",
"search_type": "support",
"spec_version": 1,
"status": "production",
"version": "1.0"
}