Data Source: Windows Event Log Security 4625

Logs an event when an account fails to log on to a system.

Property Value
Source XmlWinEventLog:Security
Sourcetype xmlwineventlog
Separator EventCode
+ Fields

            1
            _time
          
            3
            ActivityID
          
            5
            AuthenticationPackageName
          
            7
            Caller_Domain
          
            9
            Caller_User_Name
          
            11
            Channel
          
            13
            Computer
          
            15
            Error_Code
          
            17
            EventCode
          
            19
            EventData_Xml
          
            21
            EventID
          
            23
            EventRecordID
          
            25
            FailureReason
          
            27
            Guid
          
            29
            IpAddress
          
            31
            IpPort
          
            33
            KeyLength
          
            35
            Keywords
          
            37
            Level
          
            39
            LmPackageName
          
            41
            LogonProcessName
          
            43
            LogonType
          
            45
            Logon_ID
          
            47
            Logon_Type
          
            49
            Name
          
            51
            Opcode
          
            53
            ProcessID
          
            55
            ProcessId
          
            57
            ProcessName
          
            59
            RecordNumber
          
            61
            Source_Port
          
            63
            Source_Workstation
          
            65
            Status
          
            67
            SubStatus
          
            69
            Sub_Status
          
            71
            SubjectDomainName
          
            73
            SubjectLogonId
          
            75
            SubjectUserName
          
            77
            SubjectUserSid
          
            79
            SystemTime
          
            81
            System_Props_Xml
          
            83
            TargetDomainName
          
            85
            TargetUserName
          
            87
            TargetUserSid
          
            89
            Target_Domain
          
            91
            Target_User_Name
          
            93
            Task
          
            95
            ThreadID
          
            97
            TransmittedServices
          
            99
            Version
          
            101
            WorkstationName
          
            103
            action
          
            105
            app
          
            107
            date_hour
          
            109
            date_mday
          
            111
            date_minute
          
            113
            date_month
          
            115
            date_second
          
            117
            date_wday
          
            119
            date_year
          
            121
            date_zone
          
            123
            dest
          
            125
            dest_nt_domain
          
            127
            dvc
          
            129
            dvc_nt_host
          
            131
            event_id
          
            133
            eventtype
          
            135
            host
          
            137
            id
          
            139
            index
          
            141
            linecount
          
            143
            name
          
            145
            process
          
            147
            process_id
          
            149
            process_name
          
            151
            process_path
          
            153
            product
          
            155
            punct
          
            157
            session_id
          
            159
            signature
          
            161
            signature_id
          
            163
            source
          
            165
            sourcetype
          
            167
            splunk_server
          
            169
            src_ip
          
            171
            src_port
          
            173
            status
          
            175
            subject
          
            177
            ta_windows_action
          
            179
            ta_windows_status
          
            181
            tag
          
            183
            tag::action
          
            185
            tag::app
          
            187
            tag::eventtype
          
            189
            timeendpos
          
            191
            timestartpos
          
            193
            user
          
            195
            user_group
          
            197
            vendor
          
            199
            vendor_product
          
            201
            
          
...
not set
1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4625</EventID><Version>0</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated SystemTime='2023-03-22T20:25:15.594676400Z'/><EventRecordID>367348</EventRecordID><Correlation ActivityID='{6C54D781-5C05-0000-8CD7-546C055CD901}'/><Execution ProcessID='588' ThreadID='3564'/><Channel>Security</Channel><Computer>ar-win-8.attackrange.local</Computer><Security/></System><EventData><Data Name='SubjectUserSid'>NULL SID</Data><Data Name='SubjectUserName'>-</Data><Data Name='SubjectDomainName'>-</Data><Data Name='SubjectLogonId'>0x0</Data><Data Name='TargetUserSid'>NULL SID</Data><Data Name='TargetUserName'>Administrator</Data><Data Name='TargetDomainName'>builtin</Data><Data Name='Status'>0xc000006d</Data><Data Name='FailureReason'>%%2313</Data><Data Name='SubStatus'>0xc000006a</Data><Data Name='LogonType'>3</Data><Data Name='LogonProcessName'>NtLmSsp </Data><Data Name='AuthenticationPackageName'>NTLM</Data><Data Name='WorkstationName'>-</Data><Data Name='TransmittedServices'>-</Data><Data Name='LmPackageName'>-</Data><Data Name='KeyLength'>0</Data><Data Name='ProcessId'>0x0</Data><Data Name='ProcessName'>-</Data><Data Name='IpAddress'>10.0.1.30</Data><Data Name='IpPort'>59450</Data></EventData></Event>
zed

Source: GitHub | Version: 2