Getting Data In

Collecting Windows Events via A Forwarder but Groups are not being resolved

davidwaugh
Path Finder

Hello

I am collecting Windows Events using Windows Events Forwarding. On the Windows Event Collector I have a universal forwarder installed which is sending events to the indexers.

My Stanza in input.conf is as follows:

alt text

and contains the line

evt_resolve_ad_obj = 1

However for some events the group membership is not being translated from a SID to a user friendly group name:
alt text

The universal forwarder is 7.2.4.0

0 Karma

davidwaugh
Path Finder

Note i have looked in splunkd.log on the universal forwarder and cant see any errors.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...