Getting Data In

active directory monitoring is generating too many audit events in WinEventLog:Security

yannK
Splunk Employee
Splunk Employee

I just turned on a splunk forwarder with the active directory monitoring on my AD server.
Since the windows logs WinEventLogs:Security are generating a large number of audit success events :

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 2/14/2013 11:55:59 AM
Event ID: 879798
Task Category: Directory Service Access
Level: Information
Keywords: Audit Success
User: N/A
Computer: mydomain.com
Description: An operation was performed on an object.

I am also monitoring the WinEventLogs so those messages are hitting my license volume.
I know that I can filter then out at the indexer level, but this is still traffic.
How to avoid them.

Tags (1)
1 Solution

yannK
Splunk Employee
Splunk Employee

We found the solution : reducing the log level for the audit events in windows to avoid logging the audit success.

We changed the Directory Service Access subcategory to failure instead of success.
see http://support.microsoft.com/kb/232714

View solution in original post

yannK
Splunk Employee
Splunk Employee

We found the solution : reducing the log level for the audit events in windows to avoid logging the audit success.

We changed the Directory Service Access subcategory to failure instead of success.
see http://support.microsoft.com/kb/232714

Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...