<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5 in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251019#M1795</link>
    <description>&lt;P&gt;According to section "Resolve Active Directory objects in event log files" in all versions of this document:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorWindowsdata" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The following (direct quote) is true:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;The evt_resolve_ad_obj attribute is on by default for the Security channel.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We upgraded to 6.2.5 and discovered that THIS IS NO LONGER TRUE (and caused us a HUGE headache).  At some point between Splunk v6.? when everything was fine and v6.2.5 which is where we are now, Splunk changed (probably accidentally) the default value for parameter “evt_resolve_ad_obj” from “true” to “false”.  So once we upgraded, the automatic decoding of SIDs and GUIDs stopped happening.  If you are using Splunk for Enterprise Security or anything else that requires consistent WinEventLog Security events, this bug could be a huge problem for you.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:25:48 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-09-29T07:25:48Z</dc:date>
    <item>
      <title>[WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251019#M1795</link>
      <description>&lt;P&gt;According to section "Resolve Active Directory objects in event log files" in all versions of this document:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorWindowsdata" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The following (direct quote) is true:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;The evt_resolve_ad_obj attribute is on by default for the Security channel.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We upgraded to 6.2.5 and discovered that THIS IS NO LONGER TRUE (and caused us a HUGE headache).  At some point between Splunk v6.? when everything was fine and v6.2.5 which is where we are now, Splunk changed (probably accidentally) the default value for parameter “evt_resolve_ad_obj” from “true” to “false”.  So once we upgraded, the automatic decoding of SIDs and GUIDs stopped happening.  If you are using Splunk for Enterprise Security or anything else that requires consistent WinEventLog Security events, this bug could be a huge problem for you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251019#M1795</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-09-29T07:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: [WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251020#M1796</link>
      <description>&lt;P&gt;The solution is simple: do not rely on the default value and add the following explicit configuration string to all &lt;CODE&gt;[WinEventLog://Security]&lt;/CODE&gt; stanzas inside of &lt;CODE&gt;inputs.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;evt_resolve_ad_obj = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This can be a preventative change made to any version of Splunk so it should be made ASAP, regardless of your specific upgrade plans.  If the change is preventative you are done; if it is corrective, then you must restart all splunk instances on effected forwarders.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 00:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251020#M1796</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-01T00:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: [WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251021#M1797</link>
      <description>&lt;P&gt;After some research I've determined that this was indeed changed for all versions of 6.2.&lt;/P&gt;

&lt;P&gt;The documentation has been updated and an upgrade note has been added.&lt;/P&gt;

&lt;P&gt;Apologies for any inconvenience.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251021#M1797</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-10-01T20:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: [WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251022#M1798</link>
      <description>&lt;P&gt;This was much more than a mere "inconvenience" for my client; it was a very big problem that WOULD NOT have been so painful to isolate (and maybe not have happened at all) had the documentation here mentioned it (so these should all be updated, too!):&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.ALL-VERSIONS/ReleaseNotes/Knownissues"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.ALL-VERSIONS/ReleaseNotes/Knownissues&lt;/A&gt;&lt;BR /&gt;
I suggest a note both in the "Data Input" and "Known Issues" sections!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251022#M1798</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-01T20:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: [WinEventLog://Security] default for evt_resolve_ad_obj (Automatic Decoding of SIDs/GUIDs) broken in v6.2.5</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251023#M1799</link>
      <description>&lt;P&gt;Technically it's not a known issue, but a reversion to a previous behavior that was not caught in the documentation. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2beta/Installation/Aboutupgradingto6.2READTHISFIRST#Windows-specific_changes"&gt;It has been added&lt;/A&gt; now.&lt;/P&gt;

&lt;P&gt;Again, sincere apologies for the headache that this caused.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 20:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/WinEventLog-Security-default-for-evt-resolve-ad-obj-Automatic/m-p/251023#M1799</guid>
      <dc:creator>malmoore</dc:creator>
      <dc:date>2015-10-01T20:48:02Z</dc:date>
    </item>
  </channel>
</rss>

