Splunk Dev

Security log is full from Windows is not forwarded to Splunk

phamanh1652
Path Finder

Hello All,

We send logs from Windows to Splunk via Universal Forwarder. We want to create alerts for Event ID 1104 - The security log is full and 1105 - Log automatic backup.

However, when searching, we cannot find either of these events.

When reviewing the log files (EVTX), Event ID 1104 appears as the final entry in the archived log, while Event ID 1105 is the initial entry in the newly created EVTX file.

phamanh1652_1-1753845932886.png

Here is the configuration for log archiving:

phamanh1652_0-1753845777458.png

0 Karma

phamanh1652
Path Finder

For inputs.conf file, we've already enabled the Security log (and others). While other Security Event IDs, like those in the 472x range, are successfully searchable in Splunk, Event IDs 1104 and 1105 are conspicuously absent from search results.

phamanh1652_0-1753862993151.png

 

0 Karma

PrewinThomas
Motivator

@phamanh1652 

What's your inputs.conf look like.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

gcusello
SplunkTrust
SplunkTrust

Hi @phamanh1652 ,

I suppose that you're using the Splunk_TA_Windows, did you checked if, in the inputs.log, there's a filter on WinEventLog:Security logs: sometimes not all the EventCodes areindexed.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...