Getting Data In

Best way to Filter Windows Events before Indexing?

kiran331
Builder

Hi

We're seeing may Events with EventCode 4624 and 4634 with Account_Name ending with $ sign. Is there any value for it in Security logs OR we can filter them Out?

0 Karma

sylbaea
Communicator

Account names ending with a $ are usually reloated to computer identities
https://msdn.microsoft.com/en-us/library/cc246064.aspx

From a security perspective, it is very important to keep related events along with standard user activity as there are many ways to act as the computer system once it has been compromised (psexec, etc.) If you filter those events, you will be partially blind when monitoring possible attacks.

0 Karma

maciep
Champion

I can't answer whether there is a need for them, but others do filter out these computer accounts:
https://answers.splunk.com/answers/303882/unable-to-blacklist-windows-events-with-regex-on-u.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...