Alarm triggered when software is installed on the Windows server

Hello everybody,
How can I tell when software is being installed on a Windows server or Alarm triggered when software is installed on the Windows server.
is that possible with Gray Log?

Thank you

Yes, it’s possible. Send logs from windows server using sidecar with sender winlogbeat or nxlog, and create input Beats, find EventID which contains action of software installation, and create alert with it.

I have already done that. But the result is not clear.
EventID:7045

@farzanba

Maybe I can offer a suggestion.

As @shoothub suggested.

I have GL 4 using GELF TCP/TLS INPUT

Here is a screenshot of our streams using EventID, added other rules to filter out the white noise from Windows Event Veiwer. Microsoft attend to use the same EventID for other events.

Create Alert (Summary).

Email Notification received.

Hope that helps

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.