Getting Data In

i can't seeing Windows Event 1102

dariobuonocore9
New Member

In my Splunk Enterprise instance, i can't seeing the windows event "1102" from W10 client.

Someone can me help ?

0 Karma

mledford
Explorer

Have you verified that the event is being generated on the W10 client?

0 Karma

Anonymous
Not applicable

Is the Windows 10 in a domain?

Event 1102 is logged whenever the Security log is cleared,
REGARDLESS of the status of the Audit System Events audit policy.
Source: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>