<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk wineventlog in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652579#M225545</link>
    <description>&lt;P&gt;It's not really a Splunk related question. It's more like a material for a discussion with your windows admins.&lt;/P&gt;&lt;P&gt;For starters you can look into &lt;A href="https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2023 19:26:00 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-07-31T19:26:00Z</dc:date>
    <item>
      <title>Why are there Splunk wineventlog?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652573#M225544</link>
      <description>&lt;P&gt;Hi All, urgent help here. I check whether is any activity done by a user on a client machine, so i use this query in splunk search - [host="domain controller's server name" "user's account name"]. From the result, I see that there is multiple login/logout session within seconds and multiple Kerberos. I can confim that there is no physical user that is using the client machine. So can i ask why there is still wineventlogs (login/logout)?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 20:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652573#M225544</guid>
      <dc:creator>BryanLim</dc:creator>
      <dc:date>2023-07-31T20:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk wineventlog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652579#M225545</link>
      <description>&lt;P&gt;It's not really a Splunk related question. It's more like a material for a discussion with your windows admins.&lt;/P&gt;&lt;P&gt;For starters you can look into &lt;A href="https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 19:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652579#M225545</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-07-31T19:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there Splunk wineventlog?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652613#M225546</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259232"&gt;@BryanLim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I Agree with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;, this does't seem to be related to Splunk. Actually, I guess there are lots of reasons that could make this occur in a Windws host, such as the user perviously authenticated and the session was not ended, services running authenticated on that machine and so on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 21:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-there-Splunk-wineventlog/m-p/652613#M225546</guid>
      <dc:creator>caiosalonso</dc:creator>
      <dc:date>2023-07-31T21:59:45Z</dc:date>
    </item>
  </channel>
</rss>

