<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657693#M111309</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to look up data related to EventCode="4662", but it does not show in Splunk.&lt;/P&gt;&lt;P&gt;Additionally I checked inputs.conf on the indexer and it was not present, I copied inputs.conf from default:&lt;/P&gt;&lt;PRE&gt;[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"
index = wineventlog
renderXml=false&lt;/PRE&gt;&lt;P&gt;I have check within Windows Event Viewer on our Domain Controller that Event 4662 is present, but Splunk searches for EventCode=4662 produce no results.&lt;BR /&gt;&lt;BR /&gt;so what i want to see is the event code 4662 that in it's message contain &lt;SPAN&gt;&lt;SPAN class=""&gt;Object Type: user&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Here i will provide the event viewer logs that i want splunk to show&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;An operation was performed on an object.&lt;BR /&gt;&lt;BR /&gt;Subject :&lt;BR /&gt;  Security ID:    &amp;nbsp;&amp;nbsp; CIMBNIAGA\YT91504X&lt;BR /&gt;  Account Name:    &amp;nbsp; YT91504X&lt;BR /&gt;  Account Domain:    CIMBNIAGA&lt;BR /&gt;  Logon ID:    &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xC2D9E1AC&lt;BR /&gt;&lt;BR /&gt;Object:&lt;BR /&gt;  Object Server: DS&lt;BR /&gt;  Object Type:   user&lt;BR /&gt;  Object Name:&amp;nbsp;&amp;nbsp; CN=ADJOINADMIN,OU=Functional&amp;nbsp;&amp;nbsp; ID,OU=Special_OU,DC=cimbniaga,DC=co,DC=id&lt;BR /&gt;  Handle ID:     0x0&lt;BR /&gt;&lt;BR /&gt;Operation:&lt;BR /&gt;  Operation Type:  Object Access&lt;BR /&gt;  Accesses:    &amp;nbsp;   READ_CONTROL&lt;BR /&gt;&lt;BR /&gt;  Access Mask:   0x20000&lt;BR /&gt;  Properties:    READ_CONTROL {bf967aba-0de6-11d0-a285-00aa003049e2}&lt;BR /&gt;&lt;BR /&gt;Additional Information:&lt;BR /&gt;  Parameter 1:    -&lt;BR /&gt;  Parameter 2:  &lt;/PRE&gt;&lt;P&gt;Please help me i really got stuck i already try to delete the blacklist filtering but it's still not give me&amp;nbsp; the log that i want just like in the top &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199795"&gt;@kheo_splunk&lt;/a&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2023 07:18:35 GMT</pubDate>
    <dc:creator>ricardo_911</dc:creator>
    <dc:date>2023-09-15T07:18:35Z</dc:date>
    <item>
      <title>How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657693#M111309</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to look up data related to EventCode="4662", but it does not show in Splunk.&lt;/P&gt;&lt;P&gt;Additionally I checked inputs.conf on the indexer and it was not present, I copied inputs.conf from default:&lt;/P&gt;&lt;PRE&gt;[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"
index = wineventlog
renderXml=false&lt;/PRE&gt;&lt;P&gt;I have check within Windows Event Viewer on our Domain Controller that Event 4662 is present, but Splunk searches for EventCode=4662 produce no results.&lt;BR /&gt;&lt;BR /&gt;so what i want to see is the event code 4662 that in it's message contain &lt;SPAN&gt;&lt;SPAN class=""&gt;Object Type: user&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Here i will provide the event viewer logs that i want splunk to show&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;An operation was performed on an object.&lt;BR /&gt;&lt;BR /&gt;Subject :&lt;BR /&gt;  Security ID:    &amp;nbsp;&amp;nbsp; CIMBNIAGA\YT91504X&lt;BR /&gt;  Account Name:    &amp;nbsp; YT91504X&lt;BR /&gt;  Account Domain:    CIMBNIAGA&lt;BR /&gt;  Logon ID:    &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xC2D9E1AC&lt;BR /&gt;&lt;BR /&gt;Object:&lt;BR /&gt;  Object Server: DS&lt;BR /&gt;  Object Type:   user&lt;BR /&gt;  Object Name:&amp;nbsp;&amp;nbsp; CN=ADJOINADMIN,OU=Functional&amp;nbsp;&amp;nbsp; ID,OU=Special_OU,DC=cimbniaga,DC=co,DC=id&lt;BR /&gt;  Handle ID:     0x0&lt;BR /&gt;&lt;BR /&gt;Operation:&lt;BR /&gt;  Operation Type:  Object Access&lt;BR /&gt;  Accesses:    &amp;nbsp;   READ_CONTROL&lt;BR /&gt;&lt;BR /&gt;  Access Mask:   0x20000&lt;BR /&gt;  Properties:    READ_CONTROL {bf967aba-0de6-11d0-a285-00aa003049e2}&lt;BR /&gt;&lt;BR /&gt;Additional Information:&lt;BR /&gt;  Parameter 1:    -&lt;BR /&gt;  Parameter 2:  &lt;/PRE&gt;&lt;P&gt;Please help me i really got stuck i already try to delete the blacklist filtering but it's still not give me&amp;nbsp; the log that i want just like in the top &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199795"&gt;@kheo_splunk&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 07:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657693#M111309</guid>
      <dc:creator>ricardo_911</dc:creator>
      <dc:date>2023-09-15T07:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657719#M111312</link>
      <description>&lt;P&gt;You won't find event 4662 because they're blacklisted.&amp;nbsp; The blacklist prevents events with that code from being ingested and indexed, therefore, they cannot be searched.&lt;/P&gt;&lt;P&gt;Removing the blacklist will allow new 4662 events to be indexed, but will not do anything for the older events that happened while the blacklist was in effect.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 12:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657719#M111312</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-15T12:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657835#M111316</link>
      <description>&lt;P&gt;Yes i already try to remove the blacklist even try the whitelist but the result is still same the event code 4662 not generated at all. When my team already remove the blacklist, we also try to enumerate the active directory to see if the event generate but when we check on splunk the event still not showing up. Is there other settings or maybe the regex is wrong??&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 02:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657835#M111316</guid>
      <dc:creator>ricardo_911</dc:creator>
      <dc:date>2023-09-18T02:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657879#M111321</link>
      <description>&lt;P&gt;When you removed the blacklist setting do you also restart the forwarder(s)?&lt;/P&gt;&lt;P&gt;Are there any transform or Ingest Actions in the data path that might also be discarding the events?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 12:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/657879#M111321</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-18T12:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot event code 4662 and why the event not showing on splunk?? (Event code needed for use case)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/702258#M116166</link>
      <description>&lt;P&gt;Did this get resolved ? We are also facing the same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 10:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-event-code-4662-and-why-the-event-not/m-p/702258#M116166</guid>
      <dc:creator>Boogyman</dc:creator>
      <dc:date>2024-10-18T10:58:40Z</dc:date>
    </item>
  </channel>
</rss>

