All Apps and Add-ons

Lot of event codes are missing

julienlance
Explorer

Hello,

It seems that there's a lot of missing eventcodes in the EventCodes.csv lookup file, even in the last version of the app.
For instance, Event code between 4000 to 5000.
Why this file is not updated by Splunk and is there way to have to have an exhaustive file for our customers production environment ?

thanks for your help,

0 Karma

damann
Communicator

I just downloaded the newest Splunk App for Windows Infrastructure (Version 2.0.0) and counted 251 Eventcodes in the range [4000,5000]

I compared them with https://www.ultimatewindowssecurity.com which is a good starting point if you are looking for some infos regarding the Event Codes and found 255 Eventcodes in the range [4000,5000]

Which Eventcodes you are missing?

0 Karma

julienlance
Explorer

Hello Damann,

Thanks for your time.

For instance, in the last 24 hours :
4001,4013,4015,4016,4521

Others missing codes in another ranges :
134,404,407,408,2004,5774,5775,5781,6523,6527,6534,7050,7600,7681

Thanks !

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...