WEC - Event 4732 not showing Account Name on... Expand / Collapse
Author
Message
Posted 9/10/2017 3:58:41 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 9/11/2017 12:43:50 AM
Posts: 1, Visits: 1
Hi,
I just configured WEC (Source Initiated). I configured for the Account Management and Security Group Management. When I create a local account on a source computer it shows the account that is created. However, when I add the local account to a local group on the source computer, it generates the event 4732 with the account name shown correctly, but when I receive it on the Event Collector, i get the account name as -. I noticed this is the same for when I remove the local account from the group also.

Any idea how I can fix this?

Thanks,
TGBoy
Post #7407
Posted 10/9/2017 4:00:59 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 4/6/2016 3:55:29 AM
Posts: 2, Visits: 0
Hi, same question.
Event Collector - Windows Server 2012 R2
Post #7416
Posted 10/13/2017 9:32:24 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Administrators
Last Login: 4/13/2009 5:07:47 PM
Posts: 6, Visits: 0
According to Microsoft this is by design. See the explanation of the description fields on this event: https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4732

It says there:
Account Name [Type = UnicodeString]: distinguished name of account that was added to the group. For example: “CN=Auditor,CN=Users,DC=contoso,DC=local”. For local groups this field typically has “-“ value, even if new member is a domain account. For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is “-”.

If you are using a SIEM (I believe that Splunk extracts this data) you can probably setup a correlation rule to populate this data.
Post #7418
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 9:06am