<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140720#M28835</link>
    <description>&lt;P&gt;6.2.2 and 6.2.3 forwarder bundles the Windows TA. In %SplunkUniversalForwarder%/etc/apps/Splunk_TA_windows/default/inputs.conf there are the following stanzas&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
&lt;STRONG&gt;index = wineventlog&lt;/STRONG&gt;&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"&lt;BR /&gt;
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"&lt;BR /&gt;
&lt;STRONG&gt;index = wineventlog&lt;/STRONG&gt;&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = wineventlog&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;When you enable predefined eventlogs such as Security and System in the forwarder .msi installer, the stanzas in %SplunkUniversalForwarder/etc/apps/Splunk_TA_windows/local/inputs.conf looks like this&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;The Windows TA had not been installed on the Splunk Indexer/Searcher, therefore Splunk didn't know where to put the data.  The Windows TA was then installed on the Splunk Indexer/Searcher and data began showing up in the wineventlog index. &lt;/P&gt;

&lt;P&gt;I have since edited these files to point to a user defined index. We are now happily Splunking Windows Security data again. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 20:12:10 GMT</pubDate>
    <dc:creator>AndreaEClark</dc:creator>
    <dc:date>2020-09-28T20:12:10Z</dc:date>
    <item>
      <title>Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140715#M28830</link>
      <description>&lt;P&gt;My Help Desk relies upon using the Splunk server to assist with identifying the source machine or BYOD for account lockouts. Since we've rebuilt our servers on heartier platforms, (same names, same IP addresses, added resources to our DC VMs) none of my 2012 R2 machines are logging Windows Security Log events. &lt;/P&gt;

&lt;P&gt;Since the DCs have been upgraded to 2012 R2, none of them are logging security event logs.  The servers logged security events into indexes I created when they were still at 2008 R2. As far as the VMs, we extended system partition and allocated more procs and ram. Hardware devices where demoted and new device promoted.&lt;/P&gt;

&lt;P&gt;My Domain Controller GPOs for Advanced Audit Configuration, hasn't changed since we upgraded the DCs from 2008 R2 to 2012 R2.&lt;/P&gt;

&lt;P&gt;Advanced Audit Configuration&lt;BR /&gt;
Account Logon&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Credential Validation Success, Failure&lt;BR /&gt;
Audit Kerberos Authentication Service   Success, Failure&lt;BR /&gt;
Audit Kerberos Service Ticket Operations    Success, Failure&lt;BR /&gt;
Audit Other Account Logon Events    Success, Failure&lt;BR /&gt;
Account Management&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Application Group Management  Success, Failure&lt;BR /&gt;
Audit Computer Account Management   Success, Failure&lt;BR /&gt;
Audit Distribution Group Management Success, Failure&lt;BR /&gt;
Audit Other Account Management Events   Success, Failure&lt;BR /&gt;
Audit Security Group Management Success, Failure&lt;BR /&gt;
Audit User Account Management   Success, Failure&lt;BR /&gt;
Detailed Tracking&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Process Creation  Success, Failure&lt;BR /&gt;
Audit Process Termination   Success, Failure&lt;BR /&gt;
Audit RPC Events    Success, Failure&lt;BR /&gt;
DS Access&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Directory Service Access  Success, Failure&lt;BR /&gt;
Audit Directory Service Changes Success, Failure&lt;BR /&gt;
Logon/Logoff&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Account Lockout   Success, Failure&lt;BR /&gt;
Audit Logoff    Success, Failure&lt;BR /&gt;
Audit Logon Success, Failure&lt;BR /&gt;
Audit Other Logon/Logoff Events Success, Failure&lt;BR /&gt;
Audit Special Logon Success, Failure&lt;BR /&gt;
Object Access&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Application Generated Success, Failure&lt;BR /&gt;
Audit Certification Services    Success, Failure&lt;BR /&gt;
Audit File Share    Success, Failure&lt;BR /&gt;
Audit File System   Success, Failure&lt;BR /&gt;
Audit Kernel Object Success, Failure&lt;BR /&gt;
Audit Registry  Success, Failure&lt;BR /&gt;
Policy Change&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Audit Policy Change   Success, Failure&lt;BR /&gt;
Audit Authentication Policy Change  Success, Failure&lt;BR /&gt;
Audit Authorization Policy Change   Success, Failure&lt;BR /&gt;
Audit Other Policy Change Events    Failure&lt;BR /&gt;
Privilege Use&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit Sensitive Privilege Use   Success, Failure&lt;BR /&gt;
System&lt;BR /&gt;
Policy  Setting&lt;BR /&gt;
Audit IPsec Driver  Success, Failure&lt;BR /&gt;
Audit Other System Events   Failure&lt;BR /&gt;
Audit Security State Change Success, Failure&lt;BR /&gt;
Audit Security System Extension Success, Failure&lt;BR /&gt;
Audit System Integrity  Success, Failure&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2015 06:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140715#M28830</guid>
      <dc:creator>AndreaEClark</dc:creator>
      <dc:date>2015-06-03T06:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140716#M28831</link>
      <description>&lt;P&gt;This looks like a forwarder bug on Windows OS 2012 R2. I am receiving Active Directory data from the forwarder. When I installed/reinstalled the client I selected Security log, System log and Active Directory data. &lt;/P&gt;

&lt;P&gt;Anyone else attempted to deploy at 6.2.x Universal Forwarder to Windows 2012 R2 Domain Controllers that are forwarding to a 6.2.2. Splunk Server and not getting security log data?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2015 16:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140716#M28831</guid>
      <dc:creator>AndreaEClark</dc:creator>
      <dc:date>2015-06-03T16:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140717#M28832</link>
      <description>&lt;P&gt;Further analysis has revealed that the security logs are actually being sent to the Splunk indexer, but it is not indexing the data as a source=WinEventlog:Security or sourcetype=WinEventlog:Security. The only data in indexer is indexing is source=ActiveDirectory or sourcetype=ActiveDirectory. &lt;/P&gt;

&lt;P&gt;I'll post more as we discover more.  &lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 21:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140717#M28832</guid>
      <dc:creator>AndreaEClark</dc:creator>
      <dc:date>2015-06-04T21:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140718#M28833</link>
      <description>&lt;P&gt;Are you pulling the event log? By eventID? Can you post your query?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 21:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140718#M28833</guid>
      <dc:creator>leochan</dc:creator>
      <dc:date>2015-06-04T21:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140719#M28834</link>
      <description>&lt;P&gt;Using the following syntax.  With or without quotes, the last indexed data was from 6/1 just prior to removing the last 2008 R2 domain controller from our environment.&lt;/P&gt;

&lt;P&gt;index=* sourcetype="WinEventLog:Security"&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 13:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140719#M28834</guid>
      <dc:creator>AndreaEClark</dc:creator>
      <dc:date>2015-06-05T13:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Upgraded Windows Domain Controllers from 2008 R2 to 2012 R2, why are 6.2.2 and 6.2.3 universal forwarders not forwarding Security Event Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140720#M28835</link>
      <description>&lt;P&gt;6.2.2 and 6.2.3 forwarder bundles the Windows TA. In %SplunkUniversalForwarder%/etc/apps/Splunk_TA_windows/default/inputs.conf there are the following stanzas&lt;/P&gt;

&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
&lt;STRONG&gt;index = wineventlog&lt;/STRONG&gt;&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"&lt;BR /&gt;
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"&lt;BR /&gt;
&lt;STRONG&gt;index = wineventlog&lt;/STRONG&gt;&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index = wineventlog&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;When you enable predefined eventlogs such as Security and System in the forwarder .msi installer, the stanzas in %SplunkUniversalForwarder/etc/apps/Splunk_TA_windows/local/inputs.conf looks like this&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;The Windows TA had not been installed on the Splunk Indexer/Searcher, therefore Splunk didn't know where to put the data.  The Windows TA was then installed on the Splunk Indexer/Searcher and data began showing up in the wineventlog index. &lt;/P&gt;

&lt;P&gt;I have since edited these files to point to a user defined index. We are now happily Splunking Windows Security data again. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Upgraded-Windows-Domain-Controllers-from-2008-R2-to-2012-R2-why/m-p/140720#M28835</guid>
      <dc:creator>AndreaEClark</dc:creator>
      <dc:date>2020-09-28T20:12:10Z</dc:date>
    </item>
  </channel>
</rss>

