Getting Data In

active directory monitoring is generating too many audit events in WinEventLog:Security

yannK
Splunk Employee
Splunk Employee

I just turned on a splunk forwarder with the active directory monitoring on my AD server.
Since the windows logs WinEventLogs:Security are generating a large number of audit success events :

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 2/14/2013 11:55:59 AM
Event ID: 879798
Task Category: Directory Service Access
Level: Information
Keywords: Audit Success
User: N/A
Computer: mydomain.com
Description: An operation was performed on an object.

I am also monitoring the WinEventLogs so those messages are hitting my license volume.
I know that I can filter then out at the indexer level, but this is still traffic.
How to avoid them.

Tags (1)
1 Solution

yannK
Splunk Employee
Splunk Employee

We found the solution : reducing the log level for the audit events in windows to avoid logging the audit success.

We changed the Directory Service Access subcategory to failure instead of success.
see http://support.microsoft.com/kb/232714

View solution in original post

yannK
Splunk Employee
Splunk Employee

We found the solution : reducing the log level for the audit events in windows to avoid logging the audit success.

We changed the Directory Service Access subcategory to failure instead of success.
see http://support.microsoft.com/kb/232714

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...