<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to tranlate SID from Windows event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441239#M76934</link>
    <description>&lt;P&gt;Thanks,and  I've found a new detail in &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorWindowseventlogdata"&gt;documentation&lt;/A&gt;, I'm afraid with our GUIDs will not work, but have to try: &lt;/P&gt;

&lt;P&gt;" Splunk software cannot translate SIDs that are not in the format S-1-N-NN-NNNNNNNNNN-NNNNNNNNNN-NNNNNNNNNN-NNNN"&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2019 23:59:35 GMT</pubDate>
    <dc:creator>evelenke</dc:creator>
    <dc:date>2019-05-07T23:59:35Z</dc:date>
    <item>
      <title>How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441237#M76932</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;we need to analyze events with code &lt;CODE&gt;4662&lt;/CODE&gt; that contains accessed AD objects, unfortunately object values are presented as IDs (example - %{bf967a86-0de6-11d0-a285-00aa003049e2},  like it is presented in EventViewer).&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Will an attribute &lt;CODE&gt;evt_resolve_ad_obj = 1&lt;/CODE&gt; translate IDs (Object Name, Object Type) into names? OR it converts only Security ID?&lt;/LI&gt;
&lt;LI&gt;Is there any suggestion how to translate those IDs  to be presented as readable names in EventViewer directly?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 07 May 2019 13:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441237#M76932</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2019-05-07T13:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441238#M76933</link>
      <description>&lt;P&gt;You are correct, you need the &lt;CODE&gt;evt_resolve_ad_obj = 1&lt;/CODE&gt; setting and it will resolve EVERYTHING.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 15:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441238#M76933</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-07T15:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441239#M76934</link>
      <description>&lt;P&gt;Thanks,and  I've found a new detail in &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorWindowseventlogdata"&gt;documentation&lt;/A&gt;, I'm afraid with our GUIDs will not work, but have to try: &lt;/P&gt;

&lt;P&gt;" Splunk software cannot translate SIDs that are not in the format S-1-N-NN-NNNNNNNNNN-NNNNNNNNNN-NNNNNNNNNN-NNNN"&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 23:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441239#M76934</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2019-05-07T23:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441240#M76935</link>
      <description>&lt;P&gt;I have never seen SIDs that did not get resolved.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 01:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441240#M76935</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-08T01:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441241#M76936</link>
      <description>&lt;P&gt;DIdn't get to prove, because we've decided to grab sids and guids via &lt;CODE&gt;ldapsearch&lt;/CODE&gt; and format lookup. &lt;BR /&gt;
But thanks, accepting!&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 09:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441241#M76936</guid>
      <dc:creator>evelenke</dc:creator>
      <dc:date>2019-05-14T09:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to tranlate SID from Windows event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441242#M76937</link>
      <description>&lt;P&gt;WAIT!  Don't click accept on this answer!  We would all like to hear about your clever workaround.  That sill surely help somebody else (maybe me) in the future!&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 14:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-tranlate-SID-from-Windows-event/m-p/441242#M76937</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-14T14:53:54Z</dc:date>
    </item>
  </channel>
</rss>

