All Apps and Add-ons

Bug fix: New Local Admin Account

Yunagi
Communicator

First let me say that I really like the Security Essentials app since it is less complex and more lightweighted than the Enterprise Security app. I hope the Security Esssentials app will still receive updates in the future.

Is there a way to report bugs?

I found the following bug: When opening "Live Data" of "New Local Admin Account" and then clicking on "Open in Search" next to "Must have Local Account Management Logs (Event ID 4720)", then the underlying search specifies the Event ID 4726 instead of 4720. This check wrongly fails on my system.

1 Solution

David
Splunk Employee
Splunk Employee

Great catch! I just fixed it in my dev environment.

We're definitely going to keep updating Splunk Security Essentials.. in fact we're working on a big development right now! Look for an overhaul (while not losing any of the existing features or functionality!) in the next month or so!

View solution in original post

David
Splunk Employee
Splunk Employee

Great catch! I just fixed it in my dev environment.

We're definitely going to keep updating Splunk Security Essentials.. in fact we're working on a big development right now! Look for an overhaul (while not losing any of the existing features or functionality!) in the next month or so!

Yunagi
Communicator

I'm looking forward to it!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...