Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save trevorbryant/a60827918964854d5c1f0875e215c518 to your computer and use it in GitHub Desktop.
Save trevorbryant/a60827918964854d5c1f0875e215c518 to your computer and use it in GitHub Desktop.
Splunk dashboard for Windows Event Collection - Service Control: Start
<form>
<label>Windows Event Collection - Service Control: Start</label>
<description>Filtered search to discover started services</description>
<fieldset submitButton="false" autoRun="true">
<input type="text" token="computername" searchWhenChanged="true">
<label>Computer Name (FQDN)</label>
<default>*</default>
<initialValue>*</initialValue>
</input>
<input type="text" token="servicename" searchWhenChanged="true">
<label>Service Name</label>
<default>*</default>
<initialValue>*</initialValue>
</input>
<input type="time" token="time" searchWhenChanged="true">
<label>Time Range</label>
<default>
<earliest>-24h@h</earliest>
<latest>now</latest>
</default>
</input>
</fieldset>
<row>
<panel>
<chart>
<title>Services Installed Trend (Graphic)</title>
<search>
<query>index=windows EventCode=7045
| search ComputerName=$computername$ Service_Name=$servicename$
| timechart span=5m count by Service_Name
</query>
<earliest>$time.earliest$</earliest>
<latest>$time.latest$</latest>
<refresh>10m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="charting.chart">line</option>
<option name="charting.drilldown">none</option>
</chart>
</panel>
</row>
<row>
<panel>
<table>
<title>Stats by Service Install</title>
<search>
<query>index=windows EventCode=7045
| eval User=mvindex(User, 1)
| search ComputerName=$computername$ Service_Name=$servicename$
| stats count(Service_Name) as count by Service_Name
| sort - count
</query>
<earliest>$time.earliest$</earliest>
<latest>$time.latest$</latest>
</search>
<option name="drilldown">none</option>
</table>
</panel>
</row>
<row>
<panel>
<table>
<title>Service Installed Activities</title>
<search>
<query>index=windows EventCode=7045
| eval User=mvindex(User, 1)
| search ComputerName=$computername$ Service_Name=$servicename$
| table _time,ComputerName, Service_Account, Service_File_Name,Service_Name, Service_Start_Type, Service_Type, User
</query>
<earliest>$time.earliest$</earliest>
<latest>$time.latest$</latest>
<refresh>10m</refresh>
<refreshType>delay</refreshType>
</search>
<option name="count">100</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">cell</option>
<option name="percentagesRow">false</option>
<option name="rowNumbers">false</option>
<option name="totalsRow">false</option>
<option name="wrap">true</option>
</table>
</panel>
</row>
</form>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment