Batch File Write To System32
The search looks for a batch file (.bat) written to the Windows system directory tree.
This content is not mapped to any local saved search. Add mapping
Batch File Write To System32 Help
You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.
Open in Search