<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wineventtype_security does not exist or disabled in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383620#M3290</link>
    <description>&lt;P&gt;Thank you for your reply.  So after you said that this was a Windows TA I thought of the Splunk App for Windows. Low and behold the app is disabled.  I believe I disabled this app because it is incompatible with the Splunk App for Windows Infrastructure (even though Splunk says that the Splunk App for Windows Infrastructure v.1.5.1 is compatible with Splunk App for Windows v 5.0 and later).    I went on a whim and enabled the Splunk App for Windows again. However after doing this I got the error:  Could not load lookup=LOOKUP-app4_for_windows_security&lt;/P&gt;

&lt;P&gt;After looking at this for a bit most of the past answers involved disabling the Splunk App for Windows which leads me back to square 1.   I tried upgrading the Splunk App for Windows Infrastructure to v. 1.5.2 but getting errors doing so.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:13:11 GMT</pubDate>
    <dc:creator>romulusc</dc:creator>
    <dc:date>2020-09-30T01:13:11Z</dc:date>
    <item>
      <title>Wineventtype_security does not exist or disabled</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383618#M3288</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I am currently getting this yellow triangle warning on the corner of the "Job" section when running a query.  The error states "Wineventtype_security does not exist or is disabled".  This happens in both the native "Search and Reporting" App and the "Splunk App or Windows Infrastructure" app.  When I run one of the preset jobs in the Splunk App for Windows Infrastructure I get the same "warning" symbol and then the search results end up coming back with NO results for certain searches like "Failed Logins" for example.&lt;/P&gt;

&lt;P&gt;I have a feeling it's preventing me from performing searches having to do with AD information pertaining to Windows Security logs such as User changes (adds/changes/etc)&lt;/P&gt;

&lt;P&gt;I have some pictures to help describing what I am saying:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7315iFDBEBFDB546222E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7316i44184EE6491F905B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;If anyone could shed any light on this it would be appreciated.  I've already submitted a ticket to Splunk Support but they've hardly addressed this (too busy with vacations and whatnot).&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 12:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383618#M3288</guid>
      <dc:creator>romulusc</dc:creator>
      <dc:date>2019-07-10T12:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Wineventtype_security does not exist or disabled</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383619#M3289</link>
      <description>&lt;P&gt;That is an eventtype that exists by default in the latest Splunk TA for Windows. If it's not accessible I'd start checking the metadata for that knowledge object in the Windows TA under local, also the files permissions and ownership in conf files of the app&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 12:07:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383619#M3289</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-07-10T12:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Wineventtype_security does not exist or disabled</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383620#M3290</link>
      <description>&lt;P&gt;Thank you for your reply.  So after you said that this was a Windows TA I thought of the Splunk App for Windows. Low and behold the app is disabled.  I believe I disabled this app because it is incompatible with the Splunk App for Windows Infrastructure (even though Splunk says that the Splunk App for Windows Infrastructure v.1.5.1 is compatible with Splunk App for Windows v 5.0 and later).    I went on a whim and enabled the Splunk App for Windows again. However after doing this I got the error:  Could not load lookup=LOOKUP-app4_for_windows_security&lt;/P&gt;

&lt;P&gt;After looking at this for a bit most of the past answers involved disabling the Splunk App for Windows which leads me back to square 1.   I tried upgrading the Splunk App for Windows Infrastructure to v. 1.5.2 but getting errors doing so.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383620#M3290</guid>
      <dc:creator>romulusc</dc:creator>
      <dc:date>2020-09-30T01:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wineventtype_security does not exist or disabled</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383621#M3291</link>
      <description>&lt;P&gt;I don't get where is that lookup coming from. It is not in the most up to date app for win infra or in the Windows TA.&lt;/P&gt;

&lt;P&gt;The eventtype you had a problem before is in the TA for windows &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Make sure you install that in your search head so you can get search enrichments you want. &lt;/P&gt;

&lt;P&gt;Besides that, I'd check on your splunk env where that lookup is referred cause I really can't find it&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Wineventtype-security-does-not-exist-or-disabled/m-p/383621#M3291</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-07-11T13:43:55Z</dc:date>
    </item>
  </channel>
</rss>

