Getting Data In

SID not resolve on client server

servcisco
Loves-to-Learn Everything

Good afternoon! Installed the Splunk_TA_windows application on the server, edited the inputs1. On the SPLUNK server, the logs contain SID instead of name.

[WinEventLog: // Security]
disabled = 0
index = wineventlog
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
renderXml = false

Labels (1)
Tags (1)
0 Karma

servcisco
Loves-to-Learn Everything

Putting the setting "renderXml = true" did not help ( where can i see the reason?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The event contains what Windows sent.  There may be a setting on the Windows side to control this (but I doubt it) or setting renderXml = true may help.

---
If this reply helps you, Karma would be appreciated.
0 Karma

servcisco
Loves-to-Learn Everything

Putting the setting "renderXml = true" did not help ( where can i see the reason?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...