
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Dear all,
I am using SmartConnector 7.7.0 to capture Windows Event Viewer from Windows Server 2012R2.
For Event ID 4625 (RPD Logon Failed), We cannot see the Source Network/Hostname in SIEM.
From the Event viewer, this information is captured as Workstation Name. Why does not this information send to ESM?
Due to this limitation, we do not know exactly which computer tries logging to monitored server.
Is there anyway that we can see these information in SIEM?
Regards,
Anh
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello,
you are welcome.
Please try following procedure and let me know if you can see this information by using this method ?
https://community.softwaregrp.com/t5/Share-Documentation/How-to-Map-Additional-Data-from-Windows-Events-pdf/ta-p/1585389
Regards,
Marijo

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello,
1) Please let me know are you using Microsoft Windows Event Log – Native (WiNC) or Microsoft Windows Event Log – Unified (WUC) SmartConnector ?
2) Enable RAW events on SmartConnector and then observe if you have this information (WorkstationName) in RAW event ?
3) KB that covers enabling RAW event:
https://softwaresupport.softwaregrp.com/group/softwaresupport/search-result/-/facetsearch/document/KM1270081
Regards,
Marijo

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Marijo,
Thank you for your response.
Please find my answer as below:
1. Using SmartConnector for Windows Native
2-3. Enabled Preserve Raw Event and I can see that information in Raw Event. However, it does not show in ESM Event.
Regards,
Anh

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello,
you are welcome.
Please try following procedure and let me know if you can see this information by using this method ?
https://community.softwaregrp.com/t5/Share-Documentation/How-to-Map-Additional-Data-from-Windows-Events-pdf/ta-p/1585389
Regards,
Marijo