name: Windows Event Log Security 4769 id: 358d5520-f40b-4fa2-b799-966c030cb731 version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs Kerberos service ticket requests, including details about the requesting user, target service, and client IP address. mitre_components: - Active Directory Credential Request - User Account Authentication - Logon Session Metadata - User Account Metadata source: XmlWinEventLog:Security sourcetype: XmlWinEventLog separator: EventCode separator_value: '4769' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - _time - Channel - Computer - Error_Code - EventCode - EventData_Xml - EventID - EventRecordID - Guid - IpAddress - IpPort - Keywords - Level - LogonGuid - Name - Opcode - ProcessID - RecordNumber - ServiceName - ServiceSid - Source_Port - Source_Workstation - Status - SystemTime - System_Props_Xml - TargetDomainName - TargetUserName - Target_Domain - Target_User_Name - Task - ThreadID - TicketEncryptionType - TicketOptions - TransmittedServices - Version - action - app - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dest_nt_domain - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - name - product - punct - service - service_id - service_name - signature - signature_id - source - sourcetype - splunk_server - src - src_ip - src_nt_host - src_port - status - subject - ta_windows_action - ta_windows_status - tag - tag::action - tag::eventtype - timeendpos - timestartpos - user - user_group - vendor - vendor_product output_fields: - dest example_log: 4769001433700x8020000000000000148521Securityar-win-dc.attackrange.localAR-WIN-2$@ATTACKRANGE.LOCALATTACKRANGE.LOCALAR-WIN-2$ATTACKRANGE\AR-WIN-2$0x408100000x17::ffff:10.0.1.15591910x0{3b4ad75b-7184-6094-b975-ea3f91932ee0}-