<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: For Wineventlog, Event ID captures User info, but why does Splunk raw data show user User=NOT_TRANSLATED? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/For-Wineventlog-Event-ID-captures-User-info-but-why-does-Splunk/m-p/150122#M30527</link>
    <description>&lt;P&gt;Have you verified that the WinEventLog: Application input stanza is configured to translate:&lt;/P&gt;

&lt;P&gt;e.g.&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;BR /&gt;
 evt_resolve_ad_obj = 1&lt;/P&gt;

&lt;P&gt;inputs.conf.spec:&lt;/P&gt;

&lt;P&gt;evt_resolve_ad_obj = [1|0]&lt;BR /&gt;
* How the input should interact with Active Directory while indexing Windows&lt;BR /&gt;
  Event Log events.&lt;BR /&gt;
* If you set this setting to 1, the input resolves the Active&lt;BR /&gt;
  Directory Security IDentifier (SID) objects to their canonical names for&lt;BR /&gt;
  a specific Windows Event Log channel.&lt;BR /&gt;
* If you enable the setting, the rate at which the input reads events&lt;BR /&gt;
  on high-traffic Event Log channels can decrease. Latency can also increase&lt;BR /&gt;
  during event acquisition. This is due to the overhead involved in performing&lt;BR /&gt;
  AD translations.&lt;BR /&gt;
* When you set this setting to 1, you can optionally specify the domain&lt;BR /&gt;
  controller name or dns name of the domain to bind to with the 'evt_dc_name'&lt;BR /&gt;
  setting.  The input connects to that domain controller to resolve the AD&lt;BR /&gt;
  objects.&lt;BR /&gt;
* If you set this setting to 0, the input does not attempt any resolution.&lt;BR /&gt;
* Defaults to 0 (disabled) for all channels.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:35:53 GMT</pubDate>
    <dc:creator>dgrubb_splunk</dc:creator>
    <dc:date>2020-09-29T12:35:53Z</dc:date>
    <item>
      <title>For Wineventlog, Event ID captures User info, but why does Splunk raw data show user User=NOT_TRANSLATED?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/For-Wineventlog-Event-ID-captures-User-info-but-why-does-Splunk/m-p/150121#M30526</link>
      <description>&lt;P&gt;Issue is that for the Wineventlog for Application channel EventCode=11707 and EventCode=11724, intermittently _raw data User is reported as “User=NOT_TRANSLATED”&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/For-Wineventlog-Event-ID-captures-User-info-but-why-does-Splunk/m-p/150121#M30526</guid>
      <dc:creator>rbal_splunk</dc:creator>
      <dc:date>2020-09-29T06:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: For Wineventlog, Event ID captures User info, but why does Splunk raw data show user User=NOT_TRANSLATED?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/For-Wineventlog-Event-ID-captures-User-info-but-why-does-Splunk/m-p/150122#M30527</link>
      <description>&lt;P&gt;Have you verified that the WinEventLog: Application input stanza is configured to translate:&lt;/P&gt;

&lt;P&gt;e.g.&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;BR /&gt;
 evt_resolve_ad_obj = 1&lt;/P&gt;

&lt;P&gt;inputs.conf.spec:&lt;/P&gt;

&lt;P&gt;evt_resolve_ad_obj = [1|0]&lt;BR /&gt;
* How the input should interact with Active Directory while indexing Windows&lt;BR /&gt;
  Event Log events.&lt;BR /&gt;
* If you set this setting to 1, the input resolves the Active&lt;BR /&gt;
  Directory Security IDentifier (SID) objects to their canonical names for&lt;BR /&gt;
  a specific Windows Event Log channel.&lt;BR /&gt;
* If you enable the setting, the rate at which the input reads events&lt;BR /&gt;
  on high-traffic Event Log channels can decrease. Latency can also increase&lt;BR /&gt;
  during event acquisition. This is due to the overhead involved in performing&lt;BR /&gt;
  AD translations.&lt;BR /&gt;
* When you set this setting to 1, you can optionally specify the domain&lt;BR /&gt;
  controller name or dns name of the domain to bind to with the 'evt_dc_name'&lt;BR /&gt;
  setting.  The input connects to that domain controller to resolve the AD&lt;BR /&gt;
  objects.&lt;BR /&gt;
* If you set this setting to 0, the input does not attempt any resolution.&lt;BR /&gt;
* Defaults to 0 (disabled) for all channels.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/For-Wineventlog-Event-ID-captures-User-info-but-why-does-Splunk/m-p/150122#M30527</guid>
      <dc:creator>dgrubb_splunk</dc:creator>
      <dc:date>2020-09-29T12:35:53Z</dc:date>
    </item>
  </channel>
</rss>

