<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk unable to fetch Windows Security eventlogs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217433#M42780</link>
    <description>&lt;P&gt;thanks mate. We have requested the same to Windows Admin already. I'm not sure how to verify these permissions afterwards (full control is done &amp;amp; verified, read access to files verified, long as service is verified). rest of the things, I'm not sure how to verify, though they said has been done.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2016 16:15:34 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2016-09-29T16:15:34Z</dc:date>
    <item>
      <title>Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217428#M42775</link>
      <description>&lt;P&gt;We have a Windows Universal Forwader installed as service-user (svcSplunk) with read access to ALL eventlogs. (Windows 2008R2) We are getting all eventlogs except "Security" evlogs. We are struggling to find the reason for it. diags show three errors as below &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    - ERROR ExecProcessor - message from "D:\SplunkUniversalForwarder\bin\splunk-winevtlog.exe" splunk-winevtlog - WinEventLogChannel::init: Init failed, unable to subscribe to Windows Event Log channel 'security': errorCode=5
   -  ERROR ExecProcessor - Couldn't start command "D:\SplunkUniversalForwarder\bin\splunk-admon.exe": The media is write protected.
   -  ERROR ExecProcessor - message from "D:\SplunkUniversalForwarder\bin\splunk-winevtlog.exe" splunk-winevtlog - WinEventLogChannel::init: Failed to bind to DC, dc_bind_time=12106 msec    
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've tested the recommendations in below URL too, but it is NOT related to Security Softwares running:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/248673/why-is-the-splunk-universal-forwarder-on-my-domain.html"&gt;https://answers.splunk.com/answers/248673/why-is-the-splunk-universal-forwarder-on-my-domain.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;any help would be much appreciated&lt;/P&gt;

&lt;P&gt;============ update ============&lt;BR /&gt;
PS:  (the other options/test we tried already)&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; Windows Application, system eventlogs are read and working correctly. Problem is ONLY with Wineventlog:Security&lt;/LI&gt;
&lt;LI&gt;With admin permissions everything works perfect including Security logs&lt;/LI&gt;
&lt;LI&gt;No Security softwares running&lt;/LI&gt;
&lt;LI&gt;Created an interactive "&lt;EM&gt;test&lt;/EM&gt;" user with same level of permissions as &lt;EM&gt;svcSplunk&lt;/EM&gt;. As "&lt;EM&gt;test&lt;/EM&gt;" user, eventlogs are readable&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:01:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217428#M42775</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-09-29T15:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217429#M42776</link>
      <description>&lt;P&gt;What happens if you run the Forwarder with domain admin permissions just as a test?&lt;/P&gt;

&lt;P&gt;On Windows UF you should only need to changes the splunkd service account in windows services.msc and the account should have those user rights assignments :&lt;/P&gt;

&lt;P&gt;Full control over Splunk's installation directory&lt;BR /&gt;
Read access to any flat files you want to index&lt;BR /&gt;
Permission to log on as a service&lt;BR /&gt;
Permission to log on as a batch job&lt;BR /&gt;
Permission to replace a process-level token&lt;BR /&gt;
Permission to act as part of the operating system&lt;BR /&gt;
Permission to bypass traverse checking&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 15:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217429#M42776</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2016-09-29T15:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217430#M42777</link>
      <description>&lt;P&gt;with admin permissions everything works perfect. I will update this to the main query&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 16:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217430#M42777</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-09-29T16:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217431#M42778</link>
      <description>&lt;P&gt;So just work with your various permissions until you find the right settings and you should be good.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 16:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217431#M42778</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2016-09-29T16:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217432#M42779</link>
      <description>&lt;P&gt;I listed the proper settings above.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 16:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217432#M42779</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2016-09-29T16:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217433#M42780</link>
      <description>&lt;P&gt;thanks mate. We have requested the same to Windows Admin already. I'm not sure how to verify these permissions afterwards (full control is done &amp;amp; verified, read access to files verified, long as service is verified). rest of the things, I'm not sure how to verify, though they said has been done.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 16:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217433#M42780</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-09-29T16:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217434#M42781</link>
      <description>&lt;P&gt;Our Windows Admin found the reason&lt;BR /&gt;
This happens when your Windows Server Systems were migrated from Windows 2003 to Windows 2008&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;In Win2003, there are lot of SDDL's for custom controls and eventlog access. With advent of Win2008R2, Microsoft replaced it with the 'Event Log Readers' group and group policies expected to remove the old SDDL's. However, in Win2003 it had forced it originally it was tattooed in the registry and therefore the new 'Event Log Readers' group did not appear in that SDDL&lt;/LI&gt;
&lt;LI&gt;Splunk UF was succesfully gaining access to Application and System logs due to 'Service User' (any account that has 'logon as a service' permission) being present in  SDDLs, but not present in the Security log.&lt;/LI&gt;
&lt;LI&gt;The solution was to export the old SDDLs for each log and appended the access for event log readers&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 21 Oct 2016 19:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217434#M42781</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2016-10-21T19:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to fetch Windows Security eventlogs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217435#M42782</link>
      <description>&lt;P&gt;We had a similar problem: Splunk running as local system could not access WinEventLog:Security (But it could access "all" the other logs)&lt;/P&gt;

&lt;P&gt;Eventually we ran "wevtutil gl security" and realised that "Local System" did not have access.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 06:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unable-to-fetch-Windows-Security-eventlogs/m-p/217435#M42782</guid>
      <dc:creator>jonny_lyse</dc:creator>
      <dc:date>2017-09-01T06:07:10Z</dc:date>
    </item>
  </channel>
</rss>

