<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows events and %%something entries in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-events-and-something-entries/m-p/569329#M100969</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I'm using TA for Windows and everything is mostly working OK. But.&lt;/P&gt;&lt;P&gt;In some events I'm receiving values like&lt;/P&gt;&lt;TABLE width="200px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="121px"&gt;&lt;A href="https://splunkse.orlen.pl:8443/en-GB/app/search/search?q=search%20index%3Dot_ad%20source_site%3Dot_ec%20host%3DECSYSLOG%20EventID%3D5379&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.events.timelineEarliestTime=1633092060&amp;amp;display.events.timelineLatestTime=1633092120&amp;amp;sid=1633092282.36918_254179F7-77B7-4BD5-B7D6-336AE8A0F7FF#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;ReadOperation&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="79px"&gt;&lt;A href="https://splunkse.orlen.pl:8443/en-GB/app/search/search?q=search%20index%3Dot_ad%20source_site%3Dot_ec%20host%3DECSYSLOG%20EventID%3D5379&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.events.timelineEarliestTime=1633092060&amp;amp;display.events.timelineLatestTime=1633092120&amp;amp;sid=1633092282.36918_254179F7-77B7-4BD5-B7D6-336AE8A0F7FF#" target="_blank" rel="noopener"&gt;%%8100&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If I understand correctly, that's _not_ what evt_resolve_ad_obj option should affect, right? That option affects only resolving (or not) SID-s to usernames/groups and this is something completely different, right?&lt;/P&gt;&lt;P&gt;What is it then? And can I force my UF to forward the same contents that I see in Event Log Viewer?&lt;/P&gt;&lt;P&gt;In this case it's&lt;/P&gt;&lt;P&gt;Read Operation: Enumerate Credentials&lt;/P&gt;&lt;P&gt;I understand that it's something that event log viewer is rendering on its own, because in detail view of the event, it does indeed show %%8100 as ReadOperation so it's apparently the program's intepretation of this data that says "Enumerate Credentials".&lt;/P&gt;&lt;P&gt;So I suppose there'd have to be some lookups to "humanize" the events, right?&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2021 12:56:58 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-10-01T12:56:58Z</dc:date>
    <item>
      <title>Windows events and %%something entries</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-events-and-something-entries/m-p/569329#M100969</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I'm using TA for Windows and everything is mostly working OK. But.&lt;/P&gt;&lt;P&gt;In some events I'm receiving values like&lt;/P&gt;&lt;TABLE width="200px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="121px"&gt;&lt;A href="https://splunkse.orlen.pl:8443/en-GB/app/search/search?q=search%20index%3Dot_ad%20source_site%3Dot_ec%20host%3DECSYSLOG%20EventID%3D5379&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.events.timelineEarliestTime=1633092060&amp;amp;display.events.timelineLatestTime=1633092120&amp;amp;sid=1633092282.36918_254179F7-77B7-4BD5-B7D6-336AE8A0F7FF#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;ReadOperation&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="79px"&gt;&lt;A href="https://splunkse.orlen.pl:8443/en-GB/app/search/search?q=search%20index%3Dot_ad%20source_site%3Dot_ec%20host%3DECSYSLOG%20EventID%3D5379&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=-4h%40m&amp;amp;latest=now&amp;amp;display.events.timelineEarliestTime=1633092060&amp;amp;display.events.timelineLatestTime=1633092120&amp;amp;sid=1633092282.36918_254179F7-77B7-4BD5-B7D6-336AE8A0F7FF#" target="_blank" rel="noopener"&gt;%%8100&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If I understand correctly, that's _not_ what evt_resolve_ad_obj option should affect, right? That option affects only resolving (or not) SID-s to usernames/groups and this is something completely different, right?&lt;/P&gt;&lt;P&gt;What is it then? And can I force my UF to forward the same contents that I see in Event Log Viewer?&lt;/P&gt;&lt;P&gt;In this case it's&lt;/P&gt;&lt;P&gt;Read Operation: Enumerate Credentials&lt;/P&gt;&lt;P&gt;I understand that it's something that event log viewer is rendering on its own, because in detail view of the event, it does indeed show %%8100 as ReadOperation so it's apparently the program's intepretation of this data that says "Enumerate Credentials".&lt;/P&gt;&lt;P&gt;So I suppose there'd have to be some lookups to "humanize" the events, right?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 12:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-events-and-something-entries/m-p/569329#M100969</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-01T12:56:58Z</dc:date>
    </item>
  </channel>
</rss>

