<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/534002#M89659</link>
    <description>&lt;P&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;We recently upgraded our UFs throughout the environment to 8.1.0, and since the upgrade, none of the Windows based forwarders appear to be doing AD GUID/SID-to-value lookups. We have verified that&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;evt_resolve_ad_obj = 1&amp;nbsp;is set in inputs.conf for the&amp;nbsp;&lt;/SPAN&gt;[WinEventLog://Security] stanza&amp;nbsp;&lt;SPAN&gt;(verified with btool as well), and prior to the upgrade, the functionality was working fine. We tried installing the 8.1.1 version of the forwarder on one box as a test, but the problem persisted. Has anyone seen this or have any suggestions on what to check?&lt;BR /&gt;&lt;BR /&gt;This is a multi-site clustered environment running Splunk Enterprise 8.0.7. Thanks for your help!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Dec 2020 22:02:02 GMT</pubDate>
    <dc:creator>abaumbusch</dc:creator>
    <dc:date>2020-12-23T22:02:02Z</dc:date>
    <item>
      <title>Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/534002#M89659</link>
      <description>&lt;P&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;We recently upgraded our UFs throughout the environment to 8.1.0, and since the upgrade, none of the Windows based forwarders appear to be doing AD GUID/SID-to-value lookups. We have verified that&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;evt_resolve_ad_obj = 1&amp;nbsp;is set in inputs.conf for the&amp;nbsp;&lt;/SPAN&gt;[WinEventLog://Security] stanza&amp;nbsp;&lt;SPAN&gt;(verified with btool as well), and prior to the upgrade, the functionality was working fine. We tried installing the 8.1.1 version of the forwarder on one box as a test, but the problem persisted. Has anyone seen this or have any suggestions on what to check?&lt;BR /&gt;&lt;BR /&gt;This is a multi-site clustered environment running Splunk Enterprise 8.0.7. Thanks for your help!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 22:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/534002#M89659</guid>
      <dc:creator>abaumbusch</dc:creator>
      <dc:date>2020-12-23T22:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535682#M89839</link>
      <description>&lt;P&gt;Have you managed to resolve this?&lt;/P&gt;&lt;P&gt;I have this exact same problem, unfortunately haven't found any other solution than downgrading to 8.0.x&lt;/P&gt;&lt;P&gt;Enabled DEBUG logging but can't find any indication of what is failing, following this article here&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/MonitorWindowseventlogdata" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/MonitorWindowseventlogdata&lt;/A&gt;&amp;nbsp;suggest&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;If you discover that SIDs are not being translated properly, you can review&amp;nbsp;&lt;/SPAN&gt;%SPLUNK_HOME%\var\log\splunkd.log&lt;SPAN&gt;&amp;nbsp;for clues on what the problem might be. Problems with SID translations appear in the&amp;nbsp;&lt;/SPAN&gt;DsCrackNamesW&lt;SPAN&gt;&amp;nbsp;API, which appear at the DEBUG logging level for&amp;nbsp;&lt;/SPAN&gt;splunkd.log&lt;SPAN&gt;, in the&amp;nbsp;&lt;/SPAN&gt;ExecProcessor&lt;SPAN&gt;&amp;nbsp;log facility. For information on how to set the DEBUG logging level to see debug logs, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/8.1.1/Troubleshooting/Enabledebuglogging" target="_blank" rel="noopener"&gt;Enable debug logging&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;in the&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;Troubleshooting Manual&lt;/I&gt;&lt;SPAN&gt;."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any suggestions appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 16:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535682#M89839</guid>
      <dc:creator>greggernigant</dc:creator>
      <dc:date>2021-01-13T16:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535684#M89840</link>
      <description>&lt;P&gt;I opened a support case with Splunk, but research on their end is still ongoing. They thought the issue might be with Windows machines on older versions of the OS (e.g. 2012), but we are seeing this on 2016 servers as well. If I do get a solutions from them, I will make sure to post it. Thanks for your response!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 17:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535684#M89840</guid>
      <dc:creator>abaumbusch</dc:creator>
      <dc:date>2021-01-13T17:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535696#M89844</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;If that helps, in my environment the issue exists on server 2016 and 2019, tried ufw 8.1.0 and the latest 8.1.1 (splunkforwarder-8.1.1-08187535c166-x64-release) without any luck.&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 18:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/535696#M89844</guid>
      <dc:creator>greggernigant</dc:creator>
      <dc:date>2021-01-13T18:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/537509#M90088</link>
      <description>&lt;P&gt;The following has been added to known issues:&lt;BR /&gt;&lt;BR /&gt;SPL-199409, SPL-199691: Windows EventLog SIDs no longer resolving after upgrade to 8.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk Devs acknowledged the bug (I work with &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/125240"&gt;@abaumbusch&lt;/a&gt;) and provided the following workarounds:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;replace the splunk-winevtlog.exe binary on an 8.1.x forwarder with a copy from an 8.0.x forwarder, OR&lt;/LI&gt;&lt;LI&gt;set 'use_old_eventlog_api' to true for any WinEventLogs that need the SID/GUID translation. It was found that this issue does not affect any channel where 'use_old_eventlog_api' is enabled.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 27 Jan 2021 23:20:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/537509#M90088</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2021-01-27T23:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/538848#M90288</link>
      <description>&lt;P&gt;Looks like this is still an issue in 8.1.2: &lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.1.2/Forwarder/KnownIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.1.2/Forwarder/KnownIssues&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 01:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/538848#M90288</guid>
      <dc:creator>mmatturro</dc:creator>
      <dc:date>2021-02-06T01:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/538868#M90289</link>
      <description>&lt;P&gt;I was told the fix may come in 8.1.3. I can confirm adding&amp;nbsp; use_old_eventlog_api = 1 to the wineventlog:security stanza in inputs conf seems to resolve the issue. I deployed this change to forwarders on test and dev systems in our environment and the sids were properly resolved.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 16:56:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/538868#M90289</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2021-02-06T16:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarders no longer performing AD GUID/SID-to-value lookups after upgrade to 8.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/556232#M92089</link>
      <description>&lt;P&gt;Do you know if using&amp;nbsp;&lt;SPAN&gt;use_old_eventlog_api caused any other issues or side effects? Any issues with field extractions?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 19:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-Forwarders-no-longer-performing-AD-GUID-SID-to/m-p/556232#M92089</guid>
      <dc:creator>pbarbuto</dc:creator>
      <dc:date>2021-06-17T19:43:05Z</dc:date>
    </item>
  </channel>
</rss>

