Windows Data Sources

Name Platform Sourcetype Source Supported TA Date
Windows Event Log AppXDeployment-Server 400 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-AppXDeploymentServer/Operational Splunk Add-on for Microsoft Windows
Windows Event Log AppXDeployment-Server 854 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-AppXDeploymentServer/Operational Splunk Add-on for Microsoft Windows
Windows Event Log AppXDeployment-Server 855 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-AppXDeploymentServer/Operational Splunk Add-on for Microsoft Windows
Windows Event Log AppXPackaging 171 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-AppxPackaging/Operational Splunk Add-on for Microsoft Windows
Powershell Script Block Logging 4104 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-PowerShell/Operational Splunk Add-on for Microsoft Windows
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 10 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 11 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 12 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 13 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 14 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 15 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 17 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 18 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 20 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 21 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 22 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 23 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 26 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 3 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 5 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 6 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 7 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 8 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Sysmon EventID 9 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational Splunk Add-on for Sysmon
Windows Event Log CAPI2 70 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-CAPI2/Operational Splunk Add-on for Microsoft Windows
Windows Event Log CAPI2 81 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-CAPI2/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1121 Windows icon Windows XmlWinEventLog WinEventLog:Microsoft-Windows-Windows Defender/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1122 Windows icon Windows XmlWinEventLog WinEventLog:Microsoft-Windows-Windows Defender/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1125 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1126 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1129 Windows icon Windows XmlWinEventLog WinEventLog:Microsoft-Windows-Windows Defender/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1131 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1132 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1133 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 1134 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Defender 5007 Windows icon Windows XmlWinEventLog WinEventLog:Microsoft-Windows-Windows Defender/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Printservice 4909 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 1100 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 1102 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4624 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4625 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4627 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4648 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4662 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4663 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4672 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4698 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4699 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4700 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4702 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4703 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4719 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4720 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4724 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4725 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4726 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4727 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4728 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4730 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4731 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4732 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4737 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4738 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4739 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4741 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4742 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4744 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4749 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4754 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4759 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4768 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4769 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4771 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4776 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4781 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4783 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4790 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4794 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4798 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4876 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4886 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4887 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4946 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4947 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 4948 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 5136 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 5137 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 5140 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 5141 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Security 5145 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log System 104 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log System 4720 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log System 4726 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log System 4728 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log System 7036 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log System 7040 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log System 7045 Windows icon Windows XmlWinEventLog XmlWinEventLog:System Splunk Add-on for Microsoft Windows
Windows Event Log TaskScheduler 201 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security Splunk Add-on for Microsoft Windows
Windows Event Log Application 15457 Windows icon Windows XmlWinEventLog XmlWinEventLog:Application Splunk Add-on for Microsoft Windows
Windows Event Log Application 17135 Windows icon Windows XmlWinEventLog XmlWinEventLog:Application Splunk Add-on for Microsoft Windows
Windows Event Log Application 8128 Windows icon Windows XmlWinEventLog XmlWinEventLog:Application Splunk Add-on for Microsoft Windows
NTLM Operational 8004 Windows icon Windows XmlWinEventLog:Microsoft-Windows-NTLM/Operational XmlWinEventLog:Microsoft-Windows-NTLM/Operational Splunk Add-on for Microsoft Windows
NTLM Operational 8005 Windows icon Windows XmlWinEventLog:Microsoft-Windows-NTLM/Operational XmlWinEventLog:Microsoft-Windows-NTLM/Operational Splunk Add-on for Microsoft Windows
NTLM Operational 8006 Windows icon Windows XmlWinEventLog:Microsoft-Windows-NTLM/Operational XmlWinEventLog:Microsoft-Windows-NTLM/Operational Splunk Add-on for Microsoft Windows
Powershell Installed IIS Modules Windows icon Windows Pwsh:InstalledIISModules powershell://AppCmdModules N/A
Powershell SIP Inventory Windows icon Windows PwSh:SubjectInterfacePackage powershell://SubjectInterfacePackage N/A
Windows Active Directory Admon Windows icon Windows ActiveDirectory ActiveDirectory Splunk Add-on for Microsoft Windows
Windows Defender Alerts Windows icon Windows mscs:azure:eventhub:defender:advancedhunting eventhub://windowsdefenderlogs Splunk add on for Microsoft Defender Advanced Hunting
Windows Event Log Application 2282 Windows icon Windows XmlWinEventLog XmlWinEventLog:Application Splunk Add-on for Microsoft Windows
Windows Event Log Application 3000 Windows icon Windows XmlWinEventLog XmlWinEventLog:Application Splunk Add-on for Microsoft Windows
Windows Event Log CertificateServicesClient 1007 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational Splunk Add-on for Microsoft Windows
Windows Event Log Microsoft Windows TerminalServices RDPClient 1024 Windows icon Windows WinEventLog WinEventLog:Microsoft-Windows-TerminalServices-RDPClient/Operational N/A
Windows Event Log Printservice 316 Windows icon Windows WinEventLog WinEventLog:Microsoft-Windows-PrintService/Admin Splunk Add-on for Microsoft Windows
Windows Event Log Printservice 808 Windows icon Windows WinEventLog WinEventLog:Microsoft-Windows-PrintService/Admin Splunk Add-on for Microsoft Windows
Windows Event Log RemoteConnectionManager 1149 Windows icon Windows wineventlog WinEventLog:Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational Splunk Add-on for Microsoft Windows
Windows Event Log TaskScheduler 200 Windows icon Windows wineventlog WinEventLog:Microsoft-Windows-TaskScheduler/Operational Splunk Add-on for Microsoft Windows
Windows IIS Windows icon Windows IIS:Configuration:Operational IIS:Configuration:Operational Splunk Add-on for Microsoft Windows
Windows IIS 29 Windows icon Windows IIS:Configuration:Operational IIS:Configuration:Operational Splunk Add-on for Microsoft Windows