<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the search bringing &amp;quot;-&amp;quot; account results for event 4625? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439554#M125041</link>
    <description>&lt;P&gt;Do you see the SID reported in those events?&lt;/P&gt;

&lt;P&gt;If so, it may be that you do not have &lt;CODE&gt;evt_resolve_ad_obj = 1&lt;/CODE&gt; set on the inputs.conf stanza for the security event log.&lt;/P&gt;

&lt;P&gt;This setting will force the Splunk UF to try to resolve the SID to a user account&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;See this post, where I made a few suggestions on how to address this&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/732772/why-are-user-details-missing-in-the-splunk-logs.html#answer-731902"&gt;https://answers.splunk.com/answers/732772/why-are-user-details-missing-in-the-splunk-logs.html#answer-731902&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 09:54:48 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2019-03-14T09:54:48Z</dc:date>
    <item>
      <title>Why is the search bringing "-" account results for event 4625?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439552#M125039</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is the search that we are using for the dashboard and it brings all events with value "-".&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=wineventlog EventCode=4625 host=* Account_Name!=*$  | stats count by Account_Name
| eventstats  sum(count) as Failures by count | table Account_Name, Failures  | sort -Failures
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please advice&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 17:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439552#M125039</guid>
      <dc:creator>sjimenezp</dc:creator>
      <dc:date>2019-03-13T17:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the search bringing "-" account results for event 4625?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439553#M125040</link>
      <description>&lt;P&gt;Advise about what?  What are your desired results?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 23:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439553#M125040</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-13T23:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the search bringing "-" account results for event 4625?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439554#M125041</link>
      <description>&lt;P&gt;Do you see the SID reported in those events?&lt;/P&gt;

&lt;P&gt;If so, it may be that you do not have &lt;CODE&gt;evt_resolve_ad_obj = 1&lt;/CODE&gt; set on the inputs.conf stanza for the security event log.&lt;/P&gt;

&lt;P&gt;This setting will force the Splunk UF to try to resolve the SID to a user account&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#Windows_Event_Log_Monitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;See this post, where I made a few suggestions on how to address this&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/732772/why-are-user-details-missing-in-the-splunk-logs.html#answer-731902"&gt;https://answers.splunk.com/answers/732772/why-are-user-details-missing-in-the-splunk-logs.html#answer-731902&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 09:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-search-bringing-quot-quot-account-results-for-event/m-p/439554#M125041</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-14T09:54:48Z</dc:date>
    </item>
  </channel>
</rss>

