<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sudden excessive WinEventLog:Security events involving splunkd.exe in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363119#M66174</link>
    <description>&lt;P&gt;The excessive WinEventLog:Security events started the day some updates were pushed to the machine:&lt;BR /&gt;
Microsoft Security Update for .NET &lt;BR /&gt;
McAfee product updates (including Firewall update)&lt;/P&gt;

&lt;P&gt;Hmm... But it could have been something else that triggered it too.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2017 21:01:23 GMT</pubDate>
    <dc:creator>nk-1</dc:creator>
    <dc:date>2017-10-03T21:01:23Z</dc:date>
    <item>
      <title>Sudden excessive WinEventLog:Security events involving splunkd.exe</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363117#M66172</link>
      <description>&lt;P&gt;Splunk Universal Forwarder is v6.4.x&lt;BR /&gt;
Splunk Server is v6.5.x&lt;/P&gt;

&lt;P&gt;In C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf , I have:&lt;/P&gt;

&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = wmi&lt;/P&gt;

&lt;P&gt;I would normally see about 240 WinEventLog://Security "splunkd.exe" events logged per hour (for weeks).&lt;BR /&gt;
Suddenly, that number jumped to over 4 million WinEventLog://Security "splunkd.exe" events logged per hour, and my indexing limit was exceeded.&lt;/P&gt;

&lt;P&gt;Here's what gets logged:&lt;/P&gt;

&lt;P&gt;TIMESTAMP&lt;BR /&gt;
LogName=Security&lt;BR /&gt;
SourceName=Microsoft Windows security auditing.&lt;BR /&gt;
EventCode=5156&lt;BR /&gt;
EventType=0&lt;BR /&gt;
Type=Information &lt;BR /&gt;
ComputerName=HOSTNAME &lt;BR /&gt;
TaskCategory=Filtering Platform Connection &lt;BR /&gt;
OpCode=Info &lt;BR /&gt;
RecordNumber=X&lt;BR /&gt;
Keywords=Audit Success &lt;BR /&gt;
Message=The Windows Filtering Platform has permitted a connection. &lt;/P&gt;

&lt;P&gt;Application Information: &lt;BR /&gt;
  Process ID:   XXX &lt;BR /&gt;
  Application Name: \device\harddiskvolume2\program files\splunkuniversalforwarder\bin\splunkd.exe &lt;/P&gt;

&lt;P&gt;Network Information: &lt;BR /&gt;
  Direction:    Outbound &lt;BR /&gt;
  Source Address:   10.X.X.X &lt;BR /&gt;
  Source Port:  XXX &lt;BR /&gt;
  Destination Address:  172.X.X.X &lt;BR /&gt;
  Destination Port: XXX &lt;BR /&gt;
  Protocol: 6 &lt;/P&gt;

&lt;P&gt;Filter Information: &lt;BR /&gt;
  Filter Run-Time ID:   XXX &lt;BR /&gt;
  Layer Name:   Connect &lt;BR /&gt;
  Layer Run-Time ID:    X&lt;/P&gt;

&lt;P&gt;What could have possibly changed in a Windows machine that suddenly makes it log so much WinEventLog:Security "splunkd.exe" events?&lt;/P&gt;

&lt;P&gt;I could set disabled=1, but then I'd lose the ability to track who is logging in/out of that machine.&lt;BR /&gt;
Is there any way to just omit logging these kind of "Audit Success" / "The Windows Filtering Platform has permitted a connection" events?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:00:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363117#M66172</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2020-09-29T16:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden excessive WinEventLog:Security events involving splunkd.exe</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363118#M66173</link>
      <description>&lt;P&gt;Found an answer right here - &lt;A href="http://answers.splunk.com/answers/53422/eventcode-5156.html"&gt;http://answers.splunk.com/answers/53422/eventcode-5156.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:enable&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 00:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363118#M66173</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2017-10-03T00:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden excessive WinEventLog:Security events involving splunkd.exe</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363119#M66174</link>
      <description>&lt;P&gt;The excessive WinEventLog:Security events started the day some updates were pushed to the machine:&lt;BR /&gt;
Microsoft Security Update for .NET &lt;BR /&gt;
McAfee product updates (including Firewall update)&lt;/P&gt;

&lt;P&gt;Hmm... But it could have been something else that triggered it too.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 21:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363119#M66174</guid>
      <dc:creator>nk-1</dc:creator>
      <dc:date>2017-10-03T21:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sudden excessive WinEventLog:Security events involving splunkd.exe</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363120#M66175</link>
      <description>&lt;P&gt;Did you ever figure out why the "Application Name: \device\harddiskvolume2\program files\splunkuniversalforwarder\bin\splunkd.exe" was making excessive connections to the machine?  I have also run into this issue, but would like to know the root cause of excessive connections, and not excessive logs.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 18:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sudden-excessive-WinEventLog-Security-events-involving-splunkd/m-p/363120#M66175</guid>
      <dc:creator>chanthongphiob</dc:creator>
      <dc:date>2018-05-16T18:54:23Z</dc:date>
    </item>
  </channel>
</rss>

