Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: We have a requirement to audit all Applocker EXE and DLL events on all of our servers; how do I set up LEM to make this information available and prominent?

$
0
0

Hi Guys,

 

As Nicole mentioned, there's a few steps required in order to get the logs into LEM.


1.  Go to the Event log and right click on “EXE and DLL” and change the log location to be no spaces: %SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-AppLocker%4EXEandDLL.evtx


Step 1.jpg

 

Step 2.png

 

2. Now go into registry and add the key you will notice it just has no spaces “Microsoft-Windows-AppLocker/EXEandDLL” added in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog

 

Step 3.png

 

 

3. Edit the AppLocker connector to look like this:

 

Step 4.png

 

 

4. Save & Start the connector and you should now be able to see the logs in LEM (using the filters that Nicole refers to above)

 

Hope that helps!


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>