<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event Code 4765 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343235#M101640</link>
    <description>&lt;P&gt;Your RegEx is not as flexible as it needs to be.  Windows uses both &lt;CODE&gt;newlines&lt;/CODE&gt; and &lt;CODE&gt;linefeeds&lt;/CODE&gt; (it is a long, sad story).  Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Group:[\r\n\s]+Security ID:\s+([^\r\n\s]+)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 22 Apr 2018 19:33:08 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-04-22T19:33:08Z</dc:date>
    <item>
      <title>Windows Event Code 4765</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343232#M101637</link>
      <description>&lt;P&gt;I am having an issue trying to get the group name for windows security event ID 4765.  I am a little new to using regex so I am not sure why it is not working.  I used &lt;A href="http://regex101.com" target="_blank"&gt;http://regex101.com&lt;/A&gt; to help build the regex and it seemed to work.  But when I went to run in in Splunk I didn't get any results.  &lt;/P&gt;

&lt;P&gt;REGEX:&lt;BR /&gt;
Group:\n\sSecurity ID:\s\s(?[^\n]+)&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;P&gt;04/19/2018 01:21:15 PM&lt;BR /&gt;
LogName=Security&lt;BR /&gt;
SourceName=Microsoft Windows security auditing.&lt;BR /&gt;
EventCode=4756&lt;BR /&gt;
EventType=0&lt;BR /&gt;
Type=Information&lt;BR /&gt;
ComputerName=DC.ACME.COM&lt;BR /&gt;
TaskCategory=Security Group Management&lt;BR /&gt;
OpCode=Info&lt;BR /&gt;
RecordNumber=1098888999&lt;BR /&gt;
Keywords=Audit Success&lt;BR /&gt;
Message=A member was added to a security-enabled universal group.&lt;/P&gt;

&lt;P&gt;Subject:&lt;BR /&gt;
    Security ID:        ACME\HELLOWORLD&lt;BR /&gt;
    Account Name:       HELLOWORLD&lt;BR /&gt;
    Account Domain:     ACME&lt;BR /&gt;
    Logon ID:       0x33B39999&lt;/P&gt;

&lt;P&gt;Member:&lt;BR /&gt;
    Security ID:        ACME\testhello&lt;BR /&gt;
    Account Name:       CN=TESTHELLO,OU=LA,OU=ACME_USERS,DC=ACME,DC=com&lt;/P&gt;

&lt;P&gt;Group:&lt;BR /&gt;
    Security ID:        ACME\HELLO-WORLD_PP&lt;BR /&gt;
    Account Name:       HELLO-WORLD_PP&lt;BR /&gt;
    Account Domain:     ACME&lt;/P&gt;

&lt;P&gt;Additional Information:&lt;BR /&gt;
    Privileges:     -&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343232#M101637</guid>
      <dc:creator>slander00</dc:creator>
      <dc:date>2020-09-29T19:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Code 4765</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343233#M101638</link>
      <description>&lt;P&gt;are you using the windows TA?&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;BR /&gt;
supposed to have all the extractions there&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 00:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343233#M101638</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-04-20T00:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Code 4765</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343234#M101639</link>
      <description>&lt;P&gt;I am using the app but it isn't extracting a few fields for some eventcodes. I had to extract some other fields already.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 19:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343234#M101639</guid>
      <dc:creator>slander00</dc:creator>
      <dc:date>2018-04-20T19:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Code 4765</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343235#M101640</link>
      <description>&lt;P&gt;Your RegEx is not as flexible as it needs to be.  Windows uses both &lt;CODE&gt;newlines&lt;/CODE&gt; and &lt;CODE&gt;linefeeds&lt;/CODE&gt; (it is a long, sad story).  Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Group:[\r\n\s]+Security ID:\s+([^\r\n\s]+)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 22 Apr 2018 19:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Event-Code-4765/m-p/343235#M101640</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-04-22T19:33:08Z</dc:date>
    </item>
  </channel>
</rss>

