All Apps and Add-ons

WinEvenLog for Security EventCode IN (4768) missing parts after Certificate Thumbprint

jvmerilla
Path Finder

The log we have for WinEvenLog for Security EventCode IN (4768) is missing the parts
"Certificate information is only provided if a certificate was used for pre-authentication.

Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120. EditMore Resources"

This is after Certificate Thumbprint.

This only what we have in Splunk.

jvmerilla_0-1680514135379.png

The SEDCMD in props.conf were already commented out but still we are not getting this part in Splunk.

 

 

Labels (2)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

Have you tried to index the xml version of those event?

------------
Hope I was able to help you. If so, some karma would be appreciated.

jvmerilla
Path Finder

Hi @diogofgm ,

Thank you for the response!

We did try to index it as xml but we need to revert it back to the old format because, apparently, in xml format we are missing the "message" field.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...