<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we receiving all Windows event log data except security logs from our domain controller? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182110#M36491</link>
    <description>&lt;P&gt;In addition, version is 6.2.2 and the DC is windows server 2008 R2 (and we are trying as well on Windows Server 2012 R2) but same results.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2015 18:33:25 GMT</pubDate>
    <dc:creator>andybento</dc:creator>
    <dc:date>2015-03-20T18:33:25Z</dc:date>
    <item>
      <title>Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182109#M36490</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Having issues in not seeing our security logs from our DC. Here is our code:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled = 0
start_from = oldset
current_only = 0
checkpointInterval = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This inputs file is located under here with all the other code: &lt;BR /&gt;
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local&lt;/P&gt;

&lt;P&gt;We are receiving Application, system, etc. but no security logs. &lt;/P&gt;

&lt;P&gt;Also, we ran the following command splunk btool inputs list and see the following blacklist show up ..&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but we still are not receiving any security logs for our DC, but are receiving everything else. Can anyone shed some light into this?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182109#M36490</guid>
      <dc:creator>andybento</dc:creator>
      <dc:date>2020-09-28T19:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182110#M36491</link>
      <description>&lt;P&gt;In addition, version is 6.2.2 and the DC is windows server 2008 R2 (and we are trying as well on Windows Server 2012 R2) but same results.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 18:33:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182110#M36491</guid>
      <dc:creator>andybento</dc:creator>
      <dc:date>2015-03-20T18:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182111#M36492</link>
      <description>&lt;P&gt;Also, just removed UAC from the server 2012 R2 and able to see more sourcetype (was at 3 and now 5) but still no security event logs.... only Application, System, Directory Service, DNS Server, DNS Replication&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2015 18:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182111#M36492</guid>
      <dc:creator>andybento</dc:creator>
      <dc:date>2015-03-20T18:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182112#M36493</link>
      <description>&lt;P&gt;We have this problem too. Member servers forward their Security log just fine. It does not work on Domain Controllers.,We have the same (or similar) problem.  Member servers forward their Security Event Log events just fine. Domain Controllers do not.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182112#M36493</guid>
      <dc:creator>merter</dc:creator>
      <dc:date>2016-01-20T18:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182113#M36494</link>
      <description>&lt;P&gt;Because we run Splunk on our DCs w/a service account to be able to collect other AD related data, we had to add permissions to allow access to the security logs (since we didn't make the service account a domain admin).  Maybe this will help you:&lt;/P&gt;

&lt;P&gt;For us, we used a policy assigned to our domain controllers:  Group Policy - Computer Policy&amp;gt; Windows Settings&amp;gt; Security Settings&amp;gt; Local Policies &amp;gt; User Rights Assignment:&lt;/P&gt;

&lt;P&gt;Setting: Manage auditing and security log&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 18:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182113#M36494</guid>
      <dc:creator>mayfieldbk</dc:creator>
      <dc:date>2016-01-20T18:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182114#M36495</link>
      <description>&lt;P&gt;Simply add your Splunk user to the local built-in "Event Log Readers" group in all your domain controllers and that will grant them access to the local event logs in those servers. You can populate this via GPO too.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2016 14:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182114#M36495</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-01-21T14:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we receiving all Windows event log data except security logs from our domain controller?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182115#M36496</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;someone resolved this issue?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 07:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-receiving-all-Windows-event-log-data-except-security/m-p/182115#M36496</guid>
      <dc:creator>mbarbaro</dc:creator>
      <dc:date>2017-06-20T07:18:28Z</dc:date>
    </item>
  </channel>
</rss>

