<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event Code 4798 for Disabled Accounts in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544974#M5391</link>
    <description>&lt;P&gt;Thanks. They didn't generate any other Event Codes so I figured as such.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 18:03:08 GMT</pubDate>
    <dc:creator>michaeler</dc:creator>
    <dc:date>2021-03-23T18:03:08Z</dc:date>
    <item>
      <title>Windows Event Code 4798 for Disabled Accounts</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544964#M5388</link>
      <description>&lt;P&gt;I admin an Enterprise instance. I was adding a report for use of service/default accounts when I noticed all of the built-in accounts (Visitor, DefaultAdmin, etc) generated the Event Code 4798, EventType=Audit Success, four times a day on the workstations. All of these accounts are disabled.&lt;/P&gt;&lt;P&gt;I'm assuming this is the system verifying that the built-in accounts are still disabled but I wanted to make sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone confirm this or let me know what it actually means?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 16:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544964#M5388</guid>
      <dc:creator>michaeler</dc:creator>
      <dc:date>2021-03-23T16:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Code 4798 for Disabled Accounts</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544967#M5389</link>
      <description>&lt;P&gt;Yes, can confirm, groups are enumerated all day every day, so this traffic is relatively normal. If you are concerned: you can look to bring in AD information:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/1151/#/overview" target="_blank"&gt;https://splunkbase.splunk.com/app/1151/#/overview&lt;/A&gt;&amp;nbsp;and then look for any logins (4624, 4768,4776,etc.) searching for the disabled users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 17:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544967#M5389</guid>
      <dc:creator>hoaxm3</dc:creator>
      <dc:date>2021-03-23T17:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Code 4798 for Disabled Accounts</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544974#M5391</link>
      <description>&lt;P&gt;Thanks. They didn't generate any other Event Codes so I figured as such.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 18:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Windows-Event-Code-4798-for-Disabled-Accounts/m-p/544974#M5391</guid>
      <dc:creator>michaeler</dc:creator>
      <dc:date>2021-03-23T18:03:08Z</dc:date>
    </item>
  </channel>
</rss>

