<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257241#M406</link>
    <description>&lt;P&gt;Hi mahs33,&lt;/P&gt;

&lt;P&gt;Do you have the some sample of this log? Maybe your source do not was creating the correct log.&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2016 13:51:25 GMT</pubDate>
    <dc:creator>rafamss</dc:creator>
    <dc:date>2016-05-18T13:51:25Z</dc:date>
    <item>
      <title>Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257238#M403</link>
      <description>&lt;P&gt;When analyzing Windows event logs for logon failure events, I can see the IP address of logon failures coming in for some events, but I can't see it for some other events. Before and after logon failure events, I can see the IP, but not on failure log information. Why does the log not show IP?&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 12:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257238#M403</guid>
      <dc:creator>mahs33</dc:creator>
      <dc:date>2016-05-18T12:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257239#M404</link>
      <description>&lt;P&gt;What type of logs are you working with?&lt;/P&gt;

&lt;P&gt;By "Can't see IP address" do you mean it's not being extracted as a field, or do you mean if you look in the actual event itself there's no IP address in those?  The former may be easy to fix, the latter not so easy and may be a problem with the source data.  Still, in either case it's probably fixable but we need more detail, like examples of said logs, both the ones that are OK and the ones with missing data, etc...&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 12:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257239#M404</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-05-18T12:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257240#M405</link>
      <description>&lt;P&gt;here's the log:&lt;/P&gt;

&lt;P&gt;LogName=Security&lt;BR /&gt;
SourceName=Microsoft Windows security auditing.&lt;BR /&gt;
EventCode=4625&lt;BR /&gt;
EventType=0&lt;BR /&gt;
Type=Information&lt;BR /&gt;
ComputerName=abc.efg.com&lt;BR /&gt;
TaskCategory=Logon&lt;BR /&gt;
OpCode=Info&lt;BR /&gt;
Keywords=Audit Failure&lt;BR /&gt;
Message=An account failed to log on.&lt;/P&gt;

&lt;P&gt;Subject:&lt;BR /&gt;
    Security ID:        NULL SID&lt;BR /&gt;
    Account Name:       -&lt;BR /&gt;
    Account Domain:     -&lt;BR /&gt;
    Logon ID:       0x0&lt;/P&gt;

&lt;P&gt;Logon Type:         3&lt;/P&gt;

&lt;P&gt;Account For Which Logon Failed:&lt;BR /&gt;
    Security ID:        NULL SID&lt;BR /&gt;
    Account Name:       xxx&lt;BR /&gt;
    Account Domain:     worskstation&lt;/P&gt;

&lt;P&gt;Failure Information:&lt;BR /&gt;
    Failure Reason:     Unknown user name or bad password.&lt;BR /&gt;
    Status:         0xc000006d&lt;BR /&gt;
    Sub Status:     0xc0000064&lt;/P&gt;

&lt;P&gt;Process Information:&lt;BR /&gt;
    Caller Process ID:  0x0&lt;BR /&gt;
    Caller Process Name:    -&lt;/P&gt;

&lt;P&gt;Network Information:&lt;BR /&gt;
    Workstation Name:   workstation&lt;BR /&gt;
    Network Address:    -&lt;BR /&gt;
    Port:       -&lt;/P&gt;

&lt;P&gt;Detailed Authentication Information:&lt;BR /&gt;
    Logon Process:      NtLmSsp &lt;BR /&gt;
    Authentication Package: NTLM&lt;BR /&gt;
    Transited Services: -&lt;BR /&gt;
    Package Name (NTLM only):   -&lt;BR /&gt;
    Key Length:     0&lt;/P&gt;

&lt;P&gt;why i can't see SID Account Name, Domain,  Network Address?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 13:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257240#M405</guid>
      <dc:creator>mahs33</dc:creator>
      <dc:date>2016-05-18T13:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257241#M406</link>
      <description>&lt;P&gt;Hi mahs33,&lt;/P&gt;

&lt;P&gt;Do you have the some sample of this log? Maybe your source do not was creating the correct log.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 13:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257241#M406</guid>
      <dc:creator>rafamss</dc:creator>
      <dc:date>2016-05-18T13:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257242#M407</link>
      <description>&lt;P&gt;here's sample log:&lt;/P&gt;

&lt;P&gt;LogName=Security&lt;BR /&gt;
SourceName=Microsoft Windows security auditing.&lt;BR /&gt;
EventCode=4625&lt;BR /&gt;
EventType=0&lt;BR /&gt;
Type=Information&lt;BR /&gt;
ComputerName=abc.efg.com&lt;BR /&gt;
TaskCategory=Logon&lt;BR /&gt;
OpCode=Info&lt;BR /&gt;
Keywords=Audit Failure&lt;BR /&gt;
Message=An account failed to log on.&lt;/P&gt;

&lt;P&gt;Subject:&lt;BR /&gt;
Security ID: NULL SID&lt;BR /&gt;
Account Name: -&lt;BR /&gt;
Account Domain: -&lt;BR /&gt;
Logon ID: 0x0&lt;/P&gt;

&lt;P&gt;Logon Type: 3&lt;/P&gt;

&lt;P&gt;Account For Which Logon Failed:&lt;BR /&gt;
Security ID: NULL SID&lt;BR /&gt;
Account Name: xxx&lt;BR /&gt;
Account Domain: worskstation&lt;/P&gt;

&lt;P&gt;Failure Information:&lt;BR /&gt;
Failure Reason: Unknown user name or bad password.&lt;BR /&gt;
Status: 0xc000006d&lt;BR /&gt;
Sub Status: 0xc0000064&lt;/P&gt;

&lt;P&gt;Process Information:&lt;BR /&gt;
Caller Process ID: 0x0&lt;BR /&gt;
Caller Process Name: -&lt;/P&gt;

&lt;P&gt;Network Information:&lt;BR /&gt;
Workstation Name: workstation&lt;BR /&gt;
Network Address: -&lt;BR /&gt;
Port: -&lt;/P&gt;

&lt;P&gt;Detailed Authentication Information:&lt;BR /&gt;
Logon Process: NtLmSsp &lt;BR /&gt;
Authentication Package: NTLM&lt;BR /&gt;
Transited Services: -&lt;BR /&gt;
Package Name (NTLM only): -&lt;BR /&gt;
Key Length: 0&lt;/P&gt;

&lt;P&gt;why i can't see SID Account Name, Domain, Network Address?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 14:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257242#M407</guid>
      <dc:creator>mahs33</dc:creator>
      <dc:date>2016-05-18T14:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257243#M408</link>
      <description>&lt;P&gt;Searching for "Windows Event code 4625" and reading through some of the results indicates several reasons why.  For instance, &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Source Network Address: The IP address of the computer where the user is&lt;BR /&gt;
physically present in most cases unless this logon was initiated by a&lt;BR /&gt;
server application acting on behalf of the user. If this logon is initiated&lt;BR /&gt;
locally the IP address will sometimes be 127.0.0.1 instead of the local&lt;BR /&gt;
computer's actual IP address.  This field is also blank sometimes because&lt;BR /&gt;
Microsoft says "Not every code path in Windows Server 2003 is instrumented&lt;BR /&gt;
for IP address, so it's not always filled out."&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I don't know if that applies to later versions of Windows, too, but it very, very likely does.&lt;/P&gt;

&lt;P&gt;Also, I don't see status code "Status: 0xc000006d" in &lt;A href="https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625"&gt;this document&lt;/A&gt;, but I do see substatus 0x64 which is described as "user name does not exist".&lt;/P&gt;

&lt;P&gt;Putting all that together, I'd guess there could be &lt;/P&gt;

&lt;P&gt;A service that's misconfigured; check the host itself for possibly more information.&lt;/P&gt;

&lt;P&gt;A service that's configured properly and which does an authentication hop but that the credentials supplied by the user don't exist; not sure how to approach this problem because I don't know your systems/applications well enough.&lt;/P&gt;

&lt;P&gt;Bad luck in that you hit one of the non-instrumented code paths; check the host reporting this for more information - perhaps there are other logs available.  &lt;/P&gt;

&lt;P&gt;In all cases above, you could TRY looking at all the information surrounding that time for that host and maybe get some more information, but unfortunately Splunk can't "make up information" that doesn't exist.  At least not in a way that would be useful for you in this use case.  &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 15:08:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257243#M408</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-05-18T15:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257244#M409</link>
      <description>&lt;P&gt;Unfortunately I believe this is a windows issue and not a splunk issue :(. just had this problem come up myself. Look here: &lt;A href="http://serverfault.com/questions/379092/remote-desktop-failed-logon-event-4625-not-logging-ip-address-on-2008-terminal-s/403638#403638"&gt;http://serverfault.com/questions/379092/remote-desktop-failed-logon-event-4625-not-logging-ip-address-on-2008-terminal-s/403638#403638&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 21:54:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257244#M409</guid>
      <dc:creator>ph0tiC</dc:creator>
      <dc:date>2016-06-14T21:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to see the IP Address for Logon failure accounts in Windows event log information?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257245#M410</link>
      <description>&lt;P&gt;what was the search that was used in splunk to look for failed log on attempts from windows logs? I'm new to splunk and need to get this info from my network.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 15:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-unable-to-see-the-IP-Address-for-Logon-failure-accounts/m-p/257245#M410</guid>
      <dc:creator>scoota0424</dc:creator>
      <dc:date>2016-06-23T15:45:35Z</dc:date>
    </item>
  </channel>
</rss>

