SPL
Unintended Windows Shutdowns
Description
This splunk query will show any unintended Windows system Shutdowns.
Ensure the Splunk App for Windows is installed, you can grab it here: https://apps.splunk.com/app/742/
2 2
sourcetype="WinEventLog:system" EventCode=6008 | eval Date=strftime(_time, "%Y/%m/%d") | table Date host, index, Message | sort - Date
Comments
0 total
Be the first to comment on this SPL.
Leave a comment
You must log in to post a comment.