name: Windows Event Log Security 4672 id: 43f189b6-369d-4a32-a34c-57e0d38d92f1 version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk description: Data source object for Windows Event Log Security 4672 source: XmlWinEventLog:Security sourcetype: xmlwineventlog separator: EventCode supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 8.9.0 fields: - _time - ActivityID - Caller_Domain - Caller_User_Name - Channel - Computer - Error_Code - EventCode - EventData_Xml - EventID - EventRecordID - Guid - Keywords - Level - Logon_ID - Name - Opcode - PrivilegeList - ProcessID - RecordNumber - SubjectDomainName - SubjectLogonId - SubjectUserName - SubjectUserSid - SystemTime - System_Props_Xml - Task - ThreadID - Version - action - app - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - name - product - punct - session_id - signature - signature_id - source - sourcetype - splunk_server - src_nt_domain - src_user - status - subject - ta_windows_action - tag - tag::action - tag::eventtype - timeendpos - timestartpos - vendor - vendor_product example_log: 4672001254800x8020000000000000148946Securityar-win-6.attackrange.localATTACKRANGE\REED_MORSEREED_MORSEATTACKRANGE0x509b11SeSecurityPrivilege