<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290537#M55417</link>
    <description>&lt;P&gt;Hello Kitteh,&lt;/P&gt;

&lt;P&gt;To be able to provide some insight on the issue that you are currently experiencing please understand that Windows XP has not been a Support Operating System since Splunk 5.x for 64bit versions of XP &amp;amp; Splunk 6.0.14 for 32bit version of XP.  The following is the last version of Splunk that Supported Windows XP:&lt;/P&gt;

&lt;P&gt;Windows XP, 2003, Vista, Windows 7, 2008, 2008 R2 (64-bit)  5.0.18&lt;BR /&gt;
Windows XP, 2003, Vista, Windows 7, 2008 (32-bit)   6.0.14:&lt;/P&gt;

&lt;P&gt;If you are using any other version of Splunk on those Windows XP Systems this could cause the type of issue being seen.  Can you advise of the version of Splunk that you are currently using on those Windows XP Systems as again this could be the direct cause of what you are experiencing.  &lt;/P&gt;

&lt;P&gt;What could be happening here, if you are using a newer version of Splunk and the Windows TA, could be caused by changes made to the way the Windows Event Viewer functions in Newer Versions of Windows which is what the Windows TA is designed for.  &lt;/P&gt;

&lt;P&gt;Once there is clarification on the version of Splunk being used this may provide further insight in regards to the issue being seen.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2017 17:45:21 GMT</pubDate>
    <dc:creator>jethompson_splu</dc:creator>
    <dc:date>2017-11-20T17:45:21Z</dc:date>
    <item>
      <title>Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290535#M55415</link>
      <description>&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled=0&lt;BR /&gt;
start_from=oldest&lt;BR /&gt;
current_only=0&lt;BR /&gt;
evt_resolve_ad_obj=0&lt;BR /&gt;
checkpointInterval=5&lt;BR /&gt;
whitelist1=528, 529, 538, 592 ,593, 624, 630, 636, 637, 513&lt;BR /&gt;
index = winsecurity&lt;BR /&gt;
renderXml=false&lt;/P&gt;

&lt;P&gt;Above is my configuration in inputs.conf. I suppose evt_resolve_ad_obj is to prevent any resolving of GUID etc? But however it doesn't work! How do I fix this, this is for Windows XP.&lt;/P&gt;

&lt;P&gt;Left is the intended result I want it to be shown on Splunk but however it was converted which is what I do not want.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/218811-untitled.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290535#M55415</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2020-09-29T16:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290536#M55416</link>
      <description>&lt;P&gt;What you are seeing in the Event Viewer are IDs that have been converted for display. But what is stored locally and what is then submitted to Splunk are the SID values that you see on the right. So it's not that Splunk is converting them to GUIDs; rather, Splunk is indexing GUIDs and &lt;EM&gt;not&lt;/EM&gt; converting them. &lt;/P&gt;

&lt;P&gt;Here is a good discussion of options for converting SIDs to friendly names:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/340842/how-to-convert-sid-to-active-directory-friendly-na.html"&gt;https://answers.splunk.com/answers/340842/how-to-convert-sid-to-active-directory-friendly-na.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 17:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290536#M55416</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2017-11-20T17:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290537#M55417</link>
      <description>&lt;P&gt;Hello Kitteh,&lt;/P&gt;

&lt;P&gt;To be able to provide some insight on the issue that you are currently experiencing please understand that Windows XP has not been a Support Operating System since Splunk 5.x for 64bit versions of XP &amp;amp; Splunk 6.0.14 for 32bit version of XP.  The following is the last version of Splunk that Supported Windows XP:&lt;/P&gt;

&lt;P&gt;Windows XP, 2003, Vista, Windows 7, 2008, 2008 R2 (64-bit)  5.0.18&lt;BR /&gt;
Windows XP, 2003, Vista, Windows 7, 2008 (32-bit)   6.0.14:&lt;/P&gt;

&lt;P&gt;If you are using any other version of Splunk on those Windows XP Systems this could cause the type of issue being seen.  Can you advise of the version of Splunk that you are currently using on those Windows XP Systems as again this could be the direct cause of what you are experiencing.  &lt;/P&gt;

&lt;P&gt;What could be happening here, if you are using a newer version of Splunk and the Windows TA, could be caused by changes made to the way the Windows Event Viewer functions in Newer Versions of Windows which is what the Windows TA is designed for.  &lt;/P&gt;

&lt;P&gt;Once there is clarification on the version of Splunk being used this may provide further insight in regards to the issue being seen.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 17:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290537#M55417</guid>
      <dc:creator>jethompson_splu</dc:creator>
      <dc:date>2017-11-20T17:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290538#M55418</link>
      <description>&lt;P&gt;The issue you pointed out on version is not the issue, I was using indeed newer forwarders but have already uninstalled and grab the version you stated and it still does not work.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 01:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290538#M55418</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-11-21T01:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290539#M55419</link>
      <description>&lt;P&gt;Is there a way to have the SIDs converted without having to create/manage database lookup?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 01:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290539#M55419</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-11-21T01:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290540#M55420</link>
      <description>&lt;P&gt;From: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Installation/AboutupgradingREADTHISFIRST" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Installation/AboutupgradingREADTHISFIRST&lt;/A&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The etc_resolve_ad_obj attribute, which controls whether or not Splunk&lt;BR /&gt;
Enterprise attempts to resolve SIDs and GUIDs when it monitors event log&lt;BR /&gt;
channels, is now disabled by default for all channels. When you upgrade,&lt;BR /&gt;
any inputs.conf monitor stanzas that do not explicitly define this&lt;BR /&gt;
attribute will no longer perform this translation.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I suspect this may be a typo however, and they mean evt_resolve_ad_obj.  For the automatic translation to work, you will likely need to change this in your inputs.conf stanza from 0 to 1, like the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled=0
start_from=oldest
current_only=0
evt_resolve_ad_obj=1
checkpointInterval=5
whitelist1=528, 529, 538, 592 ,593, 624, 630, 636, 637, 513
index = winsecurity
renderXml=false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note: This attempts to resolve the object ID using the local machine's domain controller.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290540#M55420</guid>
      <dc:creator>mtulett_splunk</dc:creator>
      <dc:date>2020-09-29T16:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290541#M55421</link>
      <description>&lt;P&gt;Kitteh,&lt;/P&gt;

&lt;P&gt;Please understand that there have been some changes to the Splunk Windows TA that may not work as expected when running on a Windows XP System as its not a Supported OS at this time.  Now with that being said if you are using Splunk 6.x on the Windows XP Forwarder you would want to make sure that you have the following App/Add-ons installed:&lt;/P&gt;

&lt;P&gt;Splunk App for Windows Infrastructure&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1680/" target="_blank"&gt;https://splunkbase.splunk.com/app/1680/&lt;/A&gt; --&amp;gt; Oldest version of Splunk supported is Splunk 6.3&lt;/P&gt;

&lt;P&gt;Splunk Add-on for Microsoft Windows&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt; --&amp;gt; Oldest version of Splunk supported is Splunk 6.0&lt;/P&gt;

&lt;P&gt;The following provides further information on the Splunk Add-on for Microsoft Windows and the Supported OSes as well as installation instructions:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/4.8.4/User/Platformandhardwarerequirements" target="_blank"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/4.8.4/User/Platformandhardwarerequirements&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I would also like to point out the following from the Splunk inputs.conf Spec Page:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Inputsconf#Windows_Event_Log_Monitor" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Inputsconf#Windows_Event_Log_Monitor&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;evt_resolve_ad_obj = [1|0]
* How the input should interact with Active Directory while indexing Windows
  Event Log events.
* If you set this setting to 1, the input resolves the Active
  Directory Security IDentifier (SID) objects to their canonical names for
  a specific Windows Event Log channel.
* If you enable the setting, the rate at which the input reads events
  on high-traffic Event Log channels can decrease. Latency can also increase
  during event acquisition. This is due to the overhead involved in performing
  AD translations.
* When you set this setting to 1, you can optionally specify the domain
  controller name or dns name of the domain to bind to with the 'evt_dc_name'
  setting.  The input connects to that domain controller to resolve the AD
  objects.
* If you set this setting to 0, the input does not attempt any resolution.
* Defaults to 0 (disabled) for all channels.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;From the description of the issue that you have advised of the issue is that you are Wanting the AD SID translated into the Canonical Name.  You would need to enable the evt_resolve_ad_obj to get the Canonical Names for the Events being seen.  With this setting set to 0 (disabled) then you will see the SID/GUID of the Event Data instead of the Canonical Name.&lt;/P&gt;

&lt;P&gt;If you are not wanting the Canonical Name to display then you have the setting correct and would get the AD SID instead of the Canonical Name as you advised you are wanting to obtain.  There would be no way to obtain a Canonical Name without using AD Resolution against the AD SID inside of the Event.  The default behavior is to "NOT CONVERT" to the Canonical Name which is what you are seeing.  &lt;/P&gt;

&lt;P&gt;If you change evt_resolve_ad_obj from 0 to 1 and restart Splunk this should resolve the issue that you are seeing.  Now you will want to make sure you make this setting change on both the Universal Forwarder as well as the Indexer/s where you have the the Windows TA installed.  If after making this change you are not seeing the desired results I am going to suggest you submit a Support Case for further assistance.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:51:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290541#M55421</guid>
      <dc:creator>jethompson_splu</dc:creator>
      <dc:date>2020-09-29T16:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290542#M55422</link>
      <description>&lt;P&gt;Its set to 1 but still getting the ID instead of the resolved one.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 06:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290542#M55422</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-11-22T06:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290543#M55423</link>
      <description>&lt;P&gt;Installed the add-on and also turning value of evt_resolve_ad_obj into 1.&lt;/P&gt;

&lt;P&gt;My new stanza:&lt;BR /&gt;
[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
whitelist1 = 528, 529, 538, 540, 592 ,593, 624, 630, 636, 637&lt;BR /&gt;
index = winsecurity&lt;BR /&gt;
renderXml = false&lt;/P&gt;

&lt;P&gt;However my result is still the same.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290543#M55423</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2020-09-29T16:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows XP, Splunk keeps converting User Account Name to some random ID, how to avoid the converting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290544#M55424</link>
      <description>&lt;P&gt;Yes the evt_resolve_ad_obj has been set to 1 but it is still in SID form instead of friendly naming... This happens for Windows 2000 and XP&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-XP-Splunk-keeps-converting-User-Account-Name-to-some/m-p/290544#M55424</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2020-09-29T17:02:22Z</dc:date>
    </item>
  </channel>
</rss>

