Hello
I am collecting Windows Events using Windows Events Forwarding. On the Windows Event Collector I have a universal forwarder installed which is sending events to the indexers.
My Stanza in input.conf is as follows:
and contains the line
evt_resolve_ad_obj = 1
However for some events the group membership is not being translated from a SID to a user friendly group name:
The universal forwarder is 7.2.4.0
Note i have looked in splunkd.log on the universal forwarder and cant see any errors.