We are reviewing our Splunk logs from our domain controller, and it has been properly set up where endpoints on our network are identified in the Source_Workstation field. However, there is some activity where the field just shows "Unknown" despite activity from an actual user.
Does anyone know what this means?
↧