Getting Data In

Splunk 7.2.3 Windows event 11707 user "NOT_TRANSLATED"

lball
Explorer

I'm trying to alert on software install events, but the events are showing the user as "NOT_TRANSLATED". I get a SID, but that isn't helpful for alerting. I have a distributed SPLUNK install (not sure if that matters). How do I get the user name info translated for the events?

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...