<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search for Windows EventCode not caused by a Logon attempt in Security</title>
    <link>https://community.splunk.com/t5/Security/Search-for-Windows-EventCode-not-caused-by-a-Logon-attempt/m-p/56856#M13931</link>
    <description>&lt;P&gt;You might be able to filter your result set by looking at the "Process Name:" field.  Or post a few of your offending events to get a better look as to what you need to filter out .&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2013 16:48:03 GMT</pubDate>
    <dc:creator>JSapienza</dc:creator>
    <dc:date>2013-06-10T16:48:03Z</dc:date>
    <item>
      <title>Search for Windows EventCode not caused by a Logon attempt</title>
      <link>https://community.splunk.com/t5/Security/Search-for-Windows-EventCode-not-caused-by-a-Logon-attempt/m-p/56855#M13930</link>
      <description>&lt;P&gt;We have to search for EventCode 4656 for Windows 7 and 2008 Server.&lt;/P&gt;

&lt;P&gt;A lot of the 4656 are caused by logons (4624) and is there a way to search for 4656 and only show ones that are not caused by a logon.&lt;/P&gt;

&lt;P&gt;Lets say, dont show any 4656 within 30 seconds of a 4624.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2013 14:08:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Search-for-Windows-EventCode-not-caused-by-a-Logon-attempt/m-p/56855#M13930</guid>
      <dc:creator>mitchmd1</dc:creator>
      <dc:date>2013-06-06T14:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Search for Windows EventCode not caused by a Logon attempt</title>
      <link>https://community.splunk.com/t5/Security/Search-for-Windows-EventCode-not-caused-by-a-Logon-attempt/m-p/56856#M13931</link>
      <description>&lt;P&gt;You might be able to filter your result set by looking at the "Process Name:" field.  Or post a few of your offending events to get a better look as to what you need to filter out .&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2013 16:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Search-for-Windows-EventCode-not-caused-by-a-Logon-attempt/m-p/56856#M13931</guid>
      <dc:creator>JSapienza</dc:creator>
      <dc:date>2013-06-10T16:48:03Z</dc:date>
    </item>
  </channel>
</rss>

