We have noticed that some Windows Domain Controller server event logs are not appearing in the Splunk search.
For example, we conducted testing on Event ID 4724, and what we noticed is that the event is logged sometimes and sometimes it isn't. what could be the issue? Has anyone faced this before
Hi @mshakeb ,
I suppose that you're ingesting logs using a Universal Forwarder.
If there isn't any issue /that you can search in _internal) UF read all the wineventlogs from the Domain Controller, so if some event is missed, you should check, if it was generated in WinEventLog.
Ciao.
Giuseppe
Hi
Data loss or intermittent event visibility can occur at several points: source generation, forwarder collection/sending, network transport, or indexer processing/filtering.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing