Skip to main content
Version: Atlas v5.1

Windows Event Intelligence

Overview

Windows Event Intelligence is an Atlas Power Utility that organizes common Windows Event operational and security signals into focused dashboards. Use it to assess activity across monitored Windows hosts before investigating a specific host, activity type, or time period.

Open Windows Event Intelligence from Power Utilities. Use the navigation menu to select Overview, Security, Application, or System. Windows Event Intelligence is available without an active Atlas license.

Capabilities

  • Review Windows host coverage and recent event activity.
  • Investigate account, logon, process, and privilege activity.
  • Review software installation and removal activity.
  • Monitor host uptime and Windows Event coverage gaps.

Configuration

Windows Event Intelligence requires the Splunk Supported Add-on for Microsoft Windows and searchable Windows Event data. Atlas Admins configure the utility in Atlas Settings by opening Configuration, expanding Power Utilities, and selecting Windows Event Intelligence.

Set the Windows Event Macro to the search expression that identifies Windows Event data in your environment. The default is index=wineventlog. This macro is used by every Windows Event Intelligence dashboard, so update it when the data is stored in other indexes or requires a more specific search expression.

Confirm that the add-on validation check passes, save the macro, and verify the expression in Splunk Search before relying on dashboard results. The configured macro must match data in the selected time range and host scope. Otherwise, panels can show no results, zero values, or N/A.

Dashboard Navigation

Each dashboard begins with summary KPIs, followed by visualizations and tables for further investigation. Use the dashboard filters to focus the results on the hosts and time periods relevant to the review.

Overview

The Overview dashboard provides a high-level posture view for monitored Windows hosts. Its KPIs summarize failed logons, account lockouts, new accounts, suspicious processes, and password resets. The event trend provides context for recent security activity.

Available filter:

  • Time Range: the period used for dashboard activity and KPI results.

Security

The Security dashboard organizes activity into Account Activity, Logon Analysis, Process Monitoring, and Privilege Tracking. Account Activity summarizes account creation, enablement, lockouts, administrator password resets, and self-service password changes, with a related trend over time.

Available filter:

  • Filter by Username: limits the selected security view to a specific user.

Application

The Application dashboard includes Software Installation Tracker, which summarizes installation and removal activity. Its KPIs identify total installs and uninstalls, elevated and non-elevated installs, after-hours activity, and affected hosts. Supporting visualizations show activity over time and the privilege breakdown.

Available filters:

  • Time Range: the period used for installation and removal activity.
  • Filter by Host: limits results to a specific Windows host.
  • Filter by Product Name: limits results to a software product.
  • Privilege Level: filters results by installation privilege level.

System

The System menu contains host-health and infrastructure-coverage dashboards.

System Health

System Health summarizes hosts reporting uptime, hosts with less than one day of uptime, average uptime, and the highest recorded uptime. The host table shows current uptime, last report time, and status for matching hosts.

Available filters:

  • Time Range: the period used for system-health results.
  • Filter by Host: limits results to a specific Windows host.

Infrastructure Details

Infrastructure Details provides a high-level inventory of Windows Event reporting. Its KPIs summarize total Windows hosts, hosts reporting Security, Application, and System data, and hosts with coverage gaps. Use its tabs to move between Overview, Security, Application, System, and Coverage Gaps views.

Available filters:

  • Time Range: the period used for infrastructure reporting.
  • Host Name: limits results to a specific Windows host.