<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to filter out Windows Event Logs that have passwords sent in cleartext? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299413#M56627</link>
    <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;In my environment, we currently send C:\windows\system32\winevt\Logs*.evtx on our windows servers over to Splunk to get indexed.&lt;/P&gt;

&lt;P&gt;Recently I was made aware that apparently somewhere within these .evtx files are cleartext passwords.  I performed the following search and sure enough, it produced a table of accounts and cleartext passwords:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=windows sourcetype=ActiveDirectory sAMAccountType=805306369  ms_Mcs_AdmPwd=* | rename ms_Mcs_AdmPwd as "Local Admin PWD" name as Hostname | dedup Hostname | table Hostname,"Local Admin PWD"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What is the best way to filter out the cleartext passwords so either those events don't get indexed OR don't show up in the clear as search results?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2017 17:08:34 GMT</pubDate>
    <dc:creator>vanderaj2</dc:creator>
    <dc:date>2017-05-17T17:08:34Z</dc:date>
    <item>
      <title>How to filter out Windows Event Logs that have passwords sent in cleartext?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299413#M56627</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;In my environment, we currently send C:\windows\system32\winevt\Logs*.evtx on our windows servers over to Splunk to get indexed.&lt;/P&gt;

&lt;P&gt;Recently I was made aware that apparently somewhere within these .evtx files are cleartext passwords.  I performed the following search and sure enough, it produced a table of accounts and cleartext passwords:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=windows sourcetype=ActiveDirectory sAMAccountType=805306369  ms_Mcs_AdmPwd=* | rename ms_Mcs_AdmPwd as "Local Admin PWD" name as Hostname | dedup Hostname | table Hostname,"Local Admin PWD"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What is the best way to filter out the cleartext passwords so either those events don't get indexed OR don't show up in the clear as search results?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 17:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299413#M56627</guid>
      <dc:creator>vanderaj2</dc:creator>
      <dc:date>2017-05-17T17:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out Windows Event Logs that have passwords sent in cleartext?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299414#M56628</link>
      <description>&lt;P&gt;@vanderaj2 filtering the clear text events out of Splunk would still expose the account at the host machine if they are being written to disk / log file in clear text. I would suggest you look at the source of the application writing the events and have them removed or hashed from the source.&lt;/P&gt;

&lt;P&gt;Until then, you can anonymize new data coming into Splunk&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.0/Data/Anonymizedata"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.0/Data/Anonymizedata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;or mask the data at search time&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/235405/how-do-i-partially-mask-or-anonymize-a-field-value.html"&gt;https://answers.splunk.com/answers/235405/how-do-i-partially-mask-or-anonymize-a-field-value.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 17:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299414#M56628</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2017-05-17T17:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out Windows Event Logs that have passwords sent in cleartext?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299415#M56629</link>
      <description>&lt;P&gt;Thank you for the response!  I'll pass that on to the Windows Admin team and take a look at the links on how to anonymize or mask that data as well.....&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 18:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299415#M56629</guid>
      <dc:creator>vanderaj2</dc:creator>
      <dc:date>2017-05-23T18:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out Windows Event Logs that have passwords sent in cleartext?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299416#M56630</link>
      <description>&lt;P&gt;@vanderaj2 - Did the answer provided by rphillips help provide a solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 16:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-Windows-Event-Logs-that-have-passwords-sent-in/m-p/299416#M56630</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-05-25T16:01:36Z</dc:date>
    </item>
  </channel>
</rss>

