You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

11 KiB

1_timehostEventCodeuserNew_Process_IDNew_Process_Name
22016-11-02T13:13:45.000-0700USEXCH-24688USEXCH-2$0xef8C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
32016-11-02T12:54:47.000-0700USEXCH-24688USEXCH-2$0x1630C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
42016-11-02T12:11:47.000-0700USEXCH-24688USEXCH-2$0x1514C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
52016-11-01T23:51:57.000-0700USEXCH-24688USEXCH-2$0xd34C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
62016-11-01T23:46:56.000-0700USEXCH-14688USEXCH-1$0xbc4C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
72016-11-02T05:07:57.000-0700USEXCH-24688USEXCH-2$0xe3cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
82016-11-01T21:52:58.000-0700USEXCH-24688USEXCH-2$0xd28C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
92016-11-02T13:17:45.000-0700USEXCH-24688USEXCH-2$0x658C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
102016-11-02T12:22:56.000-0700USEXCH-14688USEXCH-1$0x104cC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
112016-11-02T00:00:06.000-0700USEXCH-24688USEXCH-2$0x1124C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
122016-11-02T08:32:45.000-0700USEXCH-24688USEXCH-2$0x13f8C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
132016-11-02T09:54:48.000-0700USEXCH-24688USEXCH-2$0x1004C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
142016-11-02T08:12:16.000-0700USEXCH-24688USEXCH-2$0xc48C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
152016-11-02T11:33:44.000-0700USEXCH-24688USEXCH-2$0x1444C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
162016-11-02T12:18:57.000-0700USEXCH-14688USEXCH-1$0xb18C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
172016-11-02T11:32:56.000-0700USEXCH-14688USEXCH-1$0xb20C:\Windows\System32\cmd.exe
182016-11-02T07:11:56.000-0700USEXCH-14688USEXCH-1$0xe9cC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
192016-11-02T05:27:44.000-0700USEXCH-24688USEXCH-2$0x9c0C:\Program Files\SplunkUniversalForwarder\bin\splunk-winhostinfo.exe
202016-11-02T05:06:56.000-0700USEXCH-14688USEXCH-1$0xed8C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
212016-11-02T12:59:09.000-0700USEXCH-14688USEXCH-1$0x104cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
222016-11-02T13:09:19.000-0700USEXCH-14688USEXCH-1$0x11f8C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
232016-11-02T02:41:36.000-0700USEXCH-14688USEXCH-1$0x788C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
242016-11-02T01:11:37.000-0700USEXCH-14688USEXCH-1$0x2b4C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
252016-11-01T22:59:56.000-0700USEXCH-14688USEXCH-1$0xa24C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
262016-11-01T20:31:46.000-0700USEXCH-24688USEXCH-2$0x1320C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe
272016-11-02T03:52:57.000-0700USEXCH-14688USEXCH-1$0x1ad8C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
282016-11-02T01:41:56.000-0700USEXCH-24688USEXCH-2$0xc98C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
292016-11-02T10:32:48.000-0700USEXCH-24688USEXCH-2$0x1760C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
302016-11-02T09:01:48.000-0700USEXCH-24688USEXCH-2$0x16c4C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
312016-11-02T10:24:16.000-0700USEXCH-24688USEXCH-2$0x1128C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
322016-11-02T08:46:48.000-0700USEXCH-24688USEXCH-2$0x17b8C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
332016-11-02T08:13:12.000-0700USEXCH-14688USEXCH-1$0xe14C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
342016-11-02T06:14:56.000-0700USEXCH-14688USEXCH-1$0x1334C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
352016-11-01T21:01:56.000-0700USEXCH-14688USEXCH-1$0x96cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
362016-11-01T18:24:59.000-0700USEXCH-14688USEXCH-1$0x1a60C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
372016-11-02T06:44:35.000-0700USEXCH-24688USEXCH-2$0xab4C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
382016-11-02T05:13:06.000-0700USEXCH-24688USEXCH-2$0x16e8C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
392016-11-01T16:57:06.000-0700USEXCH-24688USEXCH-2$0xb5cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-MonitorNoHandle.exe
402016-11-02T06:08:57.000-0700USEXCH-14688USEXCH-1$0x1b1cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
412016-11-02T04:12:06.000-0700USEXCH-24688USEXCH-2$0x1214C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
422016-11-02T04:09:46.000-0700USEXCH-24688USEXCH-2$0xe5cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
432016-11-02T00:23:56.000-0700USEXCH-24688USEXCH-2$0xa6cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
442016-11-02T00:16:56.000-0700USEXCH-14688USEXCH-1$0x19f0C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
452016-11-01T16:14:00.000-0700USEXCH-14688USEXCH-1$0x16acC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
462016-11-01T19:29:47.000-0700USEXCH-24688USEXCH-2$0xb68C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
472016-11-02T03:30:06.000-0700USEXCH-24688USEXCH-2$0xd68C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-MonitorNoHandle.exe
482016-11-02T02:26:37.000-0700USEXCH-14688USEXCH-1$0xd94C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
492016-11-02T01:18:00.000-0700USEXCH-14688USEXCH-1$0xb58C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
502016-11-02T11:24:11.000-0700USEXCH-14688USEXCH-1$0xf4C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
512016-11-02T10:06:45.000-0700USEXCH-24688USEXCH-2$0x1750C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
522016-11-01T15:03:57.000-0700USEXCH-14688USEXCH-1$0xad4C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
532016-11-02T07:44:44.000-0700USEXCH-24688USEXCH-2$0x1148C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
542016-11-01T19:37:58.000-0700USEXCH-14688USEXCH-1$0x1a40C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
552016-11-01T19:37:56.000-0700USEXCH-24688USEXCH-2$0xb34C:\Program Files\SplunkUniversalForwarder\bin\splunk-winhostinfo.exe
562016-11-01T18:14:56.000-0700USEXCH-24688USEXCH-2$0x1258C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
572016-11-01T16:37:59.000-0700USEXCH-14688USEXCH-1$0x394C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
582016-11-01T16:37:59.000-0700USEXCH-14688USEXCH-1$0xc91C:\Windows\System32\sc.exe
592016-11-01T16:38:01.000-0700USEXCH-14688USEXCH-1$0x3deC:\Windows\System32\net.exe
602016-11-01T16:38:01.000-0700USEXCH-14688USEXCH-1$0xfc1C:\Windows\System32\quser.exe
612016-11-01T16:38:01.000-0700USEXCH-14688USEXCH-1$0x38aC:\Windows\System32\tasklist.exe
622016-11-01T16:38:02.000-0700USEXCH-14688USEXCH-1$0x83bC:\Windows\System32\ipconfig.exe
632016-11-01T16:37:00.000-0700USEXCH-14688USEXCH-1$0x35cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
642016-11-01T16:21:36.000-0700USEXCH-24688USEXCH-2$0xd4C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-MonitorNoHandle.exe
652016-11-01T17:49:36.000-0700USEXCH-24688USEXCH-2$0x11b0C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
662016-11-01T16:51:00.000-0700USEXCH-14688USEXCH-1$0x1830C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winprintmon.exe
672016-11-02T05:35:35.000-0700USEXCH-14688USEXCH-1$0xe6cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-regmon.exe
682016-11-01T19:05:36.000-0700USEXCH-24688USEXCH-2$0x848C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
692016-11-01T18:08:00.000-0700USEXCH-14688USEXCH-1$0x624C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
702016-11-01T17:17:41.000-0700USEXCH-14688USEXCH-1$0x9ccC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
712016-11-01T14:50:57.000-0700USEXCH-14688USEXCH-1$0x1850C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
722016-11-01T13:30:57.000-0700USEXCH-24688USEXCH-2$0x994C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
732016-11-02T08:07:47.000-0700USEXCH-24688USEXCH-2$0xb3cC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
742016-11-02T01:45:56.000-0700USEXCH-24688USEXCH-2$0xa20C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe
752016-11-02T01:43:56.000-0700USEXCH-14688USEXCH-1$0x16dcC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
762016-11-01T23:55:44.000-0700USEXCH-24688USEXCH-2$0x12c4C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
772016-11-01T23:14:56.000-0700USEXCH-24688USEXCH-2$0x1368C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
782016-11-01T23:04:56.000-0700USEXCH-14688USEXCH-1$0x12c4C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe
792016-11-01T18:30:06.000-0700USEXCH-24688USEXCH-2$0xcb0C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
802016-11-01T17:35:05.000-0700USEXCH-24688USEXCH-2$0x1710C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-MonitorNoHandle.exe
812016-11-01T17:20:33.000-0700USEXCH-14688USEXCH-1$0x16b4C:\Program Files\SplunkUniversalForwarder\bin\splunk-winhostinfo.exe
822016-11-02T12:47:50.000-0700USEXCH-24688USEXCH-2$0x116cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
832016-11-02T10:57:58.000-0700USEXCH-14688USEXCH-1$0x13bcC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
842016-11-02T07:29:46.000-0700USEXCH-24688USEXCH-2$0x6a8C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
852016-11-01T23:38:45.000-0700USEXCH-24688USEXCH-2$0xa20C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
862016-11-01T22:11:56.000-0700USEXCH-14688USEXCH-1$0x404C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
872016-11-02T06:22:46.000-0700USEXCH-24688USEXCH-2$0x125cC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe
882016-11-02T03:57:45.000-0700USEXCH-24688USEXCH-2$0xab0C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
892016-11-01T17:47:59.000-0700USEXCH-14688USEXCH-1$0xf40C:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-winhostinfo.exe
902016-11-01T15:05:06.000-0700USEXCH-24688USEXCH-2$0xf8cC:\Program Files\SplunkForwarderForSplunkInc\bin\splunk-netmon.exe
912016-11-01T14:28:57.000-0700USEXCH-24688USEXCH-2$0x138C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
922016-11-01T14:16:12.000-0700USEXCH-24688USEXCH-2$0x838C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe