<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ms-Mcs-AdmPwd Plaintext in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/565658#M100624</link>
    <description>&lt;LI-CODE lang="markup"&gt;[ActiveDirectory]
SEDCMD-anonymisePWD = s/ms-Mcs-AdmPwd=.*/ms-Mcs-AdmPwd=&amp;lt;redacted&amp;gt;/g&lt;/LI-CODE&gt;&lt;P&gt;Observed the same in our env. the above sedcmd works for us.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2021 11:41:31 GMT</pubDate>
    <dc:creator>janlindmnemonic</dc:creator>
    <dc:date>2021-09-02T11:41:31Z</dc:date>
    <item>
      <title>ms-Mcs-AdmPwd Plaintext in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/562704#M100275</link>
      <description>&lt;P&gt;Hi &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We use the Splunk Cloud which gets logs from two HFs, which get logs from many UFs.&lt;BR /&gt;A few of those UFs live on our Domain Controllers, which interact to some extend with the LDAP-API and get notifications, everytime an AD-Object changes (&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/working-with-active-directory-on-splunk-universal-forwarders.html" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/working-with-active-directory-on-splunk-universal-forwarders.html&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;What now happens is, every time LAPS changes the passwords, the Computer-Object gets updated, the UF gets ahold of those Passwords and we can see them plaintext in Splunk Cloud.&lt;/P&gt;&lt;P&gt;After discovering this, i added this to props.conf (Splunk\etc\system\local) on the HF and restarted the HF :&lt;/P&gt;&lt;P&gt;[ActiveDirectory]&lt;BR /&gt;SEDCMD-pwdmask = s/(ms\-Mcs\-AdmPwd\=).+/########/g&lt;/P&gt;&lt;P&gt;And since this hasn't worked, I tried this :&lt;/P&gt;&lt;P&gt;[ActiveDirectory]&lt;BR /&gt;SEDCMD-anonymiseLaps = 's/ms-Mcs-AdmPwd\=.*/ms-Mcs-AdmPwd=####!!!!!#####/g'&lt;BR /&gt;(Source: &lt;A href="https://www.databl.io/anonymise-your-clear-text-laps-passwords-in-splunk/" target="_blank" rel="noopener"&gt;https://www.databl.io/anonymise-your-clear-text-laps-passwords-in-splunk/&lt;/A&gt;&amp;nbsp;- this describes the problem pretty well.)&lt;/P&gt;&lt;P&gt;...which hasn't worked either.&lt;BR /&gt;We still see those Passwords.&lt;/P&gt;&lt;P&gt;Has anybody encountered similar problems and/or has hints or possible solutions?&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 06:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/562704#M100275</guid>
      <dc:creator>v0c1</dc:creator>
      <dc:date>2021-08-10T06:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: ms-Mcs-AdmPwd Plaintext in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/565658#M100624</link>
      <description>&lt;LI-CODE lang="markup"&gt;[ActiveDirectory]
SEDCMD-anonymisePWD = s/ms-Mcs-AdmPwd=.*/ms-Mcs-AdmPwd=&amp;lt;redacted&amp;gt;/g&lt;/LI-CODE&gt;&lt;P&gt;Observed the same in our env. the above sedcmd works for us.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 11:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/565658#M100624</guid>
      <dc:creator>janlindmnemonic</dc:creator>
      <dc:date>2021-09-02T11:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: ms-Mcs-AdmPwd Plaintext in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/575860#M101789</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237297"&gt;@v0c1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you solve the problem?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 12:11:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ms-Mcs-AdmPwd-Plaintext-in-Splunk/m-p/575860#M101789</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-22T12:11:05Z</dc:date>
    </item>
  </channel>
</rss>

