name: Windows Event Log Security 4702 id: 167e378e-3675-4042-b611-d3bfb6d2abc7 version: 3 creation_date: '2025-03-11' modification_date: '2026-05-13' author: Steven Dick description: Data source object for Windows Event Log Security 4702 source: XmlWinEventLog:Security sourcetype: XmlWinEventLog separator: EventID supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - EventID example_log: 4702 0 0 12804 0 0x8020000000000000 344863 Security DC01.contoso.local S-1-5-21-3457937927-2839227994-823803824-1104 dadmin CONTOSO 0x364eb \\Microsoft\\StartListener 2015-09-22T19:03:06.9258653 CONTOSO\\dadmin HighestAvailable CONTOSO\\dadmin InteractiveToken IgnoreNew true true true false false true false true true false false false P3D 7 C:\\Documents\\listener.exe