Skip to main content
Warning
This app is archived. App archiving documentation
Hurricane Labs Add-on for Windows PowerShell Transcript app icon

Hurricane Labs Add-on for Windows PowerShell Transcript

This app provides knowledge objects for working with Windows PowerShell transcript logs. In addition to field extractions, a number of event types are included to support threat hunting use cases. Built by Hurricane Labs
splunk product badge

Default Version 0.1.3

May 21, 2024

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

Rating
5
(1)

Log in to rate this app

Support
Archived Add-on

This app provides knowledge objects for working with Windows PowerShell transcript logs. In addition to field extractions, a number of event types are included to support threat hunting use cases. You will need to configure your Windows systems to log PowerShell transcripts in order to benefit from this app. This logging is not enabled by default in Windows. These logs, once generated, should be collected via a file input and forwarded to Splunk. Additional information on the configuration of this app is available here: www.hurricanelabs.com/splunk-tutorials/splunk-tutorial-powershell-transcription-logging This app is also available on GitHub: https://github.com/HurricaneLabs/TA-powershell_transcript