<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication tag not being applied in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751329#M10468</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312265"&gt;@unclemoose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you seeing events with &lt;STRONG&gt;eventtype=account_locked&lt;/STRONG&gt;? If not, Make sure eventtype is saved in a visible app and permissions are set to global.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Aug 2025 03:58:47 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-08-11T03:58:47Z</dc:date>
    <item>
      <title>Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751328#M10467</link>
      <description>&lt;P&gt;I am trying to learn SIEM tech and am at the stage where im trying to use/setup Splunk CIM. My pipeline uses fake logs and I am trying to get them to show up with the Authentication data model. However it seems like the authentication tag is not being applied.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;(files shortened )&lt;BR /&gt;&lt;STRONG&gt;My eventtypes.conf:&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;[account_locked]&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"logstream"&lt;/SPAN&gt; &lt;SPAN&gt;action&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"failure"&lt;/SPAN&gt; &lt;SPAN&gt;signature&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Account locked"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;tags&lt;/SPAN&gt;&lt;SPAN&gt; = authentication, failure, account_locked&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;My tags.conf:&lt;/STRONG&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[eventtype=account_locked]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;authentication&lt;/SPAN&gt;&lt;SPAN&gt; = enabled&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;failure&lt;/SPAN&gt;&lt;SPAN&gt; = enabled&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;account_locked&lt;/SPAN&gt;&lt;SPAN&gt; = enabled&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;and my props.conf:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[logstream]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TIME_FORMAT&lt;/SPAN&gt;&lt;SPAN&gt; = %Y-%m-%dT%H:%M:%S.%6N%:z&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TIME_PREFIX&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;"\"&lt;/SPAN&gt;&lt;SPAN&gt;_time\&lt;/SPAN&gt;&lt;SPAN&gt;": \"""&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;MAX_TIMESTAMP_LOOKAHEAD&lt;/SPAN&gt;&lt;SPAN&gt; = 30&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;INDEXED_EXTRACTIONS&lt;/SPAN&gt;&lt;SPAN&gt; = json&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;FIELDALIAS-src_user_for_user&lt;/SPAN&gt;&lt;SPAN&gt; = user AS src_user&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FIELDALIAS-src_for_src&lt;/SPAN&gt;&lt;SPAN&gt; = src AS src&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FIELDALIAS-dest_for_dest&lt;/SPAN&gt;&lt;SPAN&gt; = dest AS dest&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FIELDALIAS-app_for_app&lt;/SPAN&gt;&lt;SPAN&gt; = app AS app&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;FIELDALIAS-dest_for_dest&lt;/SPAN&gt;&lt;SPAN&gt; = dest AS dest &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;Now what is really stumping me here is that no event types are being recognized. However, if I search for those logs by doing the command I used for the event type,&amp;nbsp; I get the results and logs I am looking for:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"logstream"&lt;/SPAN&gt; &lt;SPAN&gt;action&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"failure"&lt;/SPAN&gt; &lt;SPAN&gt;signature&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"Account locked"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;A couple of things I confirmed:&lt;BR /&gt;&lt;BR /&gt;- HEC token is correct&lt;BR /&gt;- The Field Aliases are compliant with the&amp;nbsp; Authentication Data Model&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 10 Aug 2025 22:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751328#M10467</guid>
      <dc:creator>unclemoose</dc:creator>
      <dc:date>2025-08-10T22:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751329#M10468</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312265"&gt;@unclemoose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you seeing events with &lt;STRONG&gt;eventtype=account_locked&lt;/STRONG&gt;? If not, Make sure eventtype is saved in a visible app and permissions are set to global.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 03:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751329#M10468</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-08-11T03:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751339#M10469</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312265"&gt;@unclemoose&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;where are you running the eventtype search: in the same app where it was created or in another one?&lt;/P&gt;&lt;P&gt;check if your eventtype is visible also outside the app where it was created, probably you shared your eventtype at app level and not at global level.&lt;/P&gt;&lt;P&gt;check the permissions of the eventtype.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 07:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751339#M10469</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-08-11T07:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751347#M10470</link>
      <description>&lt;P&gt;Apart from what has already been said about permissions, the question is what is your architecture? (all-in-one, separate indexing and search-head layer, any pre-parsing HFs?) And where did you put those props and transforms. And don't use indexed extractions unless there is absolutely no other way (not related to the problem at hand but worth remembering).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 09:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751347#M10470</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-08-11T09:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751349#M10471</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312265"&gt;@unclemoose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly, settings&amp;nbsp;&lt;SPAN&gt;tags&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;= authentication, failure, account_locked in your eventtypes.conf is deprecated, so you should probably remove this incase its causing an issue.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Secondly, I wanted to check is what search mode you are using, are you using Fast mode? If so you probably wont see the eventtypes/tag fields come back - Try running in Smart of Verbose mode - do you see the tags returned then?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Lastly, where are these files within your environment? Are they in a custom/specific app? Are you running the search from the same app as the app? Are the configurations shared globally with the system or only within its app?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 09:49:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751349#M10471</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-08-11T09:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication tag not being applied</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751359#M10472</link>
      <description>&lt;P&gt;This lead me to the solution! I tried looking for eventtype=account_locked and got nothing. Turns out that my eventtypes were not global. Not only that but I needed to make a copy of my tags.conf in the search app instead of it being local to the app [logstream].&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 18:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Authentication-tag-not-being-applied/m-p/751359#M10472</guid>
      <dc:creator>unclemoose</dc:creator>
      <dc:date>2025-08-11T18:29:10Z</dc:date>
    </item>
  </channel>
</rss>

