
It will all start with a search. I don’t quite know what Applocker events show up as in the logs, but if you do a full text search for “applocker” against your AgentX logs, hopefully there is something that you can identify - either certain labels, or perhaps the event-source field. You can limit your search to AgentX log by using norm_id=AgentX, or of course by just selecting the correct repository.
And then it is a question as to what you actually want to visualise - usually it’d be something like
norm_id=AgentX event_source=Microsoft-Windows-AppLocker |chart count() by message
or action, or account, or whatever fields you see in your AppLocker logs.
Once you have the right query, you can add it do a new dashboard widgets from the dropdown in the top right of the Search interface.
3 comments