Powershell History Logs
Last updated
Last updated
Navigate to in windows system
Add the following code
monitor - this line will monitor all power-shell histories on all users
sourcetype - can be anything
index - you will make a index in Splunk and this needs to be the same as that in my case i named the index powershellHistory
Hit settings in the top right corner > then click on indexes
Hit the button
Name the index powershellHistory in this case, also change the app to "Search & Reporting"
save
on the PC that has the forwarder go into services and find splunk forwarder service and hit restart
in the search of splunk type in