<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CIM Authentication data model in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679367#M232242</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to know the aim of this default constraint :&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;(`cim_Authentication_indexes`) tag=authentication NOT (action=success user=*$)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;action="success"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Especially what does it try to match with user=*$ ? User accounts ending with $ symbol like in Windows?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Thanks.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 02 Mar 2024 09:46:58 GMT</pubDate>
    <dc:creator>splunkreal</dc:creator>
    <dc:date>2024-03-02T09:46:58Z</dc:date>
    <item>
      <title>CIM Authentication data model</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679367#M232242</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to know the aim of this default constraint :&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;(`cim_Authentication_indexes`) tag=authentication NOT (action=success user=*$)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;action="success"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Especially what does it try to match with user=*$ ? User accounts ending with $ symbol like in Windows?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Thanks.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 02 Mar 2024 09:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679367#M232242</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2024-03-02T09:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: CIM Authentication data model</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679369#M232243</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;user names ending with $ are windows service accounts and usually they aren't relevant in authentication monitoring.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2024 11:43:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679369#M232243</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-02T11:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: CIM Authentication data model</title>
      <link>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679374#M232244</link>
      <description>&lt;P&gt;As far as I remember, there are two kinds of account that have names ending with $ (in Windows - for other systems it's highly unlikely that there will be an account named this way; but it would be nice to account for that) - Managed Service Accounts (which &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; already mentioned) and computer accounts. Both of those account types are authenticated without using interactive authentication modes so they're irrelevant to the events you're looking for in this dataset.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2024 13:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/CIM-Authentication-data-model/m-p/679374#M232244</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-03-02T13:42:10Z</dc:date>
    </item>
  </channel>
</rss>

