Wondered if anyone has built a search around Windows Event ID 1074 (shutdown event) in Splunk. Looking to build a daily report around unscheduled Windows Server reboots.
↧