All Apps and Add-ons

XMLWineventlog: How can we Map Security CategoryID and SubcategoryID?

mcfabrero_acn
Explorer

Hi,

Recently, we have changed the format of how our winventlog data is being fed to Splunk. From the classic format, we had it changed to XML. 

I found out that there is a difference in how data was also extracted when it was in classic versus when it is in XML. One would be for EventCode=4719, I noticed that before, in classic, we used to have Category and Subcategory fields but switching to XML, we are getting CategoryId and SubcategoryId. 

The challenge was, that we don't have any means to convert these IDs into their own meaning. I have been looking for any lookup that comes with the Splunk Add-on for Windows in order for me to map these ids but unfortunately can't find one. 

I tried to check Microsoft Windows documents but to no avail cannot find how to get the values for these ids.

Can anyone help how we can map the CategoryId and SubcategoryId?

Thanks in advance!

Labels (4)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Set up a field alias.

0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...