Reporting

Events are Inconsistent

gba8912
Explorer

Hello,

 

I am having an issue where sometimes I can see events and sometimes not. An example is: I tested event 4625 with my account and i can see it in Splunk, but a colleague generated the same event but it does not show up in Splunk. I can see both events in the event viewer so I am not sure why this is going on. I have made sure the search with correct time selection.

Another note: I can see other events from his account in Splunk.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...