Atlas Windows Event Intelligence
Turn Windows event data into actionable security, operational, and system insights with focused Splunk dashboards.Built by Presidio Splunk SolutionsLog in to rate this app
Windows Event Intelligence is a Power Utility included with the Atlas Software Platform for Splunk that organizes common Windows operational and security data into focused, easy-to-use dashboards. It helps administrators and security team quickly assess Windows host coverage, understand recent activity, and investigate events related to accounts, logons, processes, privileges, software changes, and system health. The utility provide dashboards for overall Windows activity monitoring, security investigations, software installation tracking, host uptime, and Windows event infrastructure coverage. Flexible filtering by time range, username, host, product, and privilege helps user quickly narrow their analysis to the systems and activity that matter most. Windows Event Intelligence requires the Splunk supported add-on for Microsoft Windows and searchable Windows event data. Windows Event Intelligence is included in the Atlas Software Platform for Splunk available on Splunkbase at https://splunkbase.splunk.com/app/5614.
Log in to report this app listing.