Splunk Search

Why are there Splunk wineventlog?

BryanLim
New Member

Hi All, urgent help here. I check whether is any activity done by a user on a client machine, so i use this query in splunk search - [host="domain controller's server name" "user's account name"]. From the result, I see that there is multiple login/logout session within seconds and multiple Kerberos. I can confim that there is no physical user that is using the client machine. So can i ask why there is still wineventlogs (login/logout)?

Tags (1)
0 Karma

caiosalonso
Path Finder

Hi @BryanLim ,

I Agree with @PickleRick, this does't seem to be related to Splunk. Actually, I guess there are lots of reasons that could make this occur in a Windws host, such as the user perviously authenticated and the session was not ended, services running authenticated on that machine and so on. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's not really a Splunk related question. It's more like a material for a discussion with your windows admins.

For starters you can look into https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-even...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...