name: Windows Security 4648 id: ed43f45a-d85d-4417-91e6-7128612d1098 date: '2022-11-28' author: Patrick Bareiss, Splunk type: wineventlog_security source: WinEventLog:Security sourcetype: WinEventLog service: security product: windows supported_TA: - name: Splunk Add-on for Microsoft Windows version: 8.5.0 url: https://splunkbase.splunk.com/app/742 references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4648 raw_fields: - Account_Domain - Account_Name - ComputerName - Logon_GUID - Logon_ID - Network_Address - Port - Security_ID - Subject_Account_Domain - Subject_Account_Name - Subject_Logon_ID - Subject_Security_ID - Target_Server_Name