Created
November 14, 2018 15:52
-
-
Save trevorbryant/a60827918964854d5c1f0875e215c518 to your computer and use it in GitHub Desktop.
Splunk dashboard for Windows Event Collection - Service Control: Start
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<form> | |
<label>Windows Event Collection - Service Control: Start</label> | |
<description>Filtered search to discover started services</description> | |
<fieldset submitButton="false" autoRun="true"> | |
<input type="text" token="computername" searchWhenChanged="true"> | |
<label>Computer Name (FQDN)</label> | |
<default>*</default> | |
<initialValue>*</initialValue> | |
</input> | |
<input type="text" token="servicename" searchWhenChanged="true"> | |
<label>Service Name</label> | |
<default>*</default> | |
<initialValue>*</initialValue> | |
</input> | |
<input type="time" token="time" searchWhenChanged="true"> | |
<label>Time Range</label> | |
<default> | |
<earliest>-24h@h</earliest> | |
<latest>now</latest> | |
</default> | |
</input> | |
</fieldset> | |
<row> | |
<panel> | |
<chart> | |
<title>Services Installed Trend (Graphic)</title> | |
<search> | |
<query>index=windows EventCode=7045 | |
| search ComputerName=$computername$ Service_Name=$servicename$ | |
| timechart span=5m count by Service_Name | |
</query> | |
<earliest>$time.earliest$</earliest> | |
<latest>$time.latest$</latest> | |
<refresh>10m</refresh> | |
<refreshType>delay</refreshType> | |
</search> | |
<option name="charting.chart">line</option> | |
<option name="charting.drilldown">none</option> | |
</chart> | |
</panel> | |
</row> | |
<row> | |
<panel> | |
<table> | |
<title>Stats by Service Install</title> | |
<search> | |
<query>index=windows EventCode=7045 | |
| eval User=mvindex(User, 1) | |
| search ComputerName=$computername$ Service_Name=$servicename$ | |
| stats count(Service_Name) as count by Service_Name | |
| sort - count | |
</query> | |
<earliest>$time.earliest$</earliest> | |
<latest>$time.latest$</latest> | |
</search> | |
<option name="drilldown">none</option> | |
</table> | |
</panel> | |
</row> | |
<row> | |
<panel> | |
<table> | |
<title>Service Installed Activities</title> | |
<search> | |
<query>index=windows EventCode=7045 | |
| eval User=mvindex(User, 1) | |
| search ComputerName=$computername$ Service_Name=$servicename$ | |
| table _time,ComputerName, Service_Account, Service_File_Name,Service_Name, Service_Start_Type, Service_Type, User | |
</query> | |
<earliest>$time.earliest$</earliest> | |
<latest>$time.latest$</latest> | |
<refresh>10m</refresh> | |
<refreshType>delay</refreshType> | |
</search> | |
<option name="count">100</option> | |
<option name="dataOverlayMode">none</option> | |
<option name="drilldown">cell</option> | |
<option name="percentagesRow">false</option> | |
<option name="rowNumbers">false</option> | |
<option name="totalsRow">false</option> | |
<option name="wrap">true</option> | |
</table> | |
</panel> | |
</row> | |
</form> |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment