Re: Issue with scripts/services/evt[application|security|system]
Orion Poplawski <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On 06/29/2011 12:48 PM, Orion Poplawski wrote: > yours: > Jun 16 12:53:30 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[0]:Security > 23 Thu Jun 16 12:53:30 2011 592 Security SYSTEM > User Success Audit IT-VM-99 Detailed Tracking A new > process has been created: New Process ID: 5352 Image File Name: > C:\WINDOWS\system32\searchprotocolhost.exe Creator Process ID: 1032 > User Name: IT-VM-99$ Domain: MY Logon ID: (0x0,0x3E7) 12 > > > mine: > Jun 26 06:19:45 TONKA MSWinEventLog 1 Application 429 Sun > Jun 26 06:19:45 2011 15 AutoEnrollment Unknown User N/A > Error TONKA None Automatic certificate enrollment for local > system failed to contact the active directory (0x8007054b). The specified > domain either does not exist or could not be contacted. Enrollment will not > be performed. 160 Actually, looking closer it definitely looks like the format has change with snare 4 (MSWinEventLog 1 Application -> MSWinEventLog[1]:Application). So this definitely needs to get handled. -- Orion Poplawski Technical Manager 303-415-9701 x222 NWRA/CoRA Division FAX: 303-415-9702 3380 Mitchell Lane [email protected] Boulder, CO 80301 http://www.cora.nwra.com ------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2