IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  DSM and trouble

    Posted 03/20/20 01:32 PM
    Hi
    Houston we have a problem!
    We have this event:
    <13>Mar 21 00:03:58 zsmk-ts-010 AgentDevice=WindowsLog AgentLogFile=Microsoft-Windows-TerminalServices-Gateway/Operational PluginVersion=7.2.9.72 Source=Microsoft-Windows-TerminalServices-Gateway Computer=zsmk-ts-010 OriginatingComputer=10.40.10.10 User=NETWORK SERVICE Domain=NT AUTHORITY EventID=302 EventIDCode=302 EventType=4 EventCategory=3 RecordNumber=117657 TimeGenerated=1584723345 TimeWritten=1584723345 Level=Informational Keywords=aag:Admin Task=aag:Adapter Opcode=30 Message=The user "maqlostvav_be", on client computer "188.123.35.211", connected to resource "ZSMK-RDCBHA-001". Connection protocol used: "HTTP".
    As you can see, event contains User=NETWORK SERVICE (https://www.ibm.com/support/pages/windows-system-events-or-username-events-display-na-username-field) and therefore username will be N / A. BUT if we look at event, there is a normal username. Made the necessary changes to the parser via DSM Editor, but the received username values ​​are ignored, as there is NETWORK SERVICE.
    Perhaps someone has already encountered such a problem? I ask for help in solving it!
    P.S.:I made a request for support, but so far they only referred to the indicated link (after I indicated it in the additions :-))
     


    ------------------------------
    Dmitriy Garanin
    ------------------------------


  • 2.  RE: DSM and trouble

    Posted 03/23/20 10:59 AM
    We have seen a few Windows events with parsing issues. We get tons of DNS queries with our Wincollect servers as the source, but that seems pretty unlikely given the queries. It appears that some of the client requests end up with the Wincollect server as the source for some reason.

    Also, like you, user names are absent from where you would expect (hope?) to see them. 

    BTW, we are just using the standard Windows security log parser, no customizations that I am aware of. 


    ------------------------------
    _____________________
    Daniel Sichel
    ------------------------------