Files
splunk-security_content/data_sources/endpoint/Windows_Security_4768.yml
2022-12-19 09:34:19 +01:00

30 lines
691 B
YAML

name: Windows Security 4768
id: e24420da-5137-4e81-b217-6a8accfe4c9c
date: '2022-11-28'
author: Patrick Bareiss, Splunk
type: wineventlog_security
source: WinEventLog:Security
sourcetype: WinEventLog
service: security
product: windows
supported_TA:
- name: Splunk Add-on for Microsoft Windows
version: 8.5.0
url: https://splunkbase.splunk.com/app/742
references:
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4768
raw_fields:
- Account_Domain
- Account_Name
- Client_Address
- Client_Port
- ComputerName
- Pre_Authentication_Type
- Result_Code
- Service_ID
- Service_Name
- Supplied_Realm_Name
- Ticket_Encryption_Type
- Ticket_Options
- User_ID