Hi Splunkers
I am getting this value of field app=win:unknown being captured in 63% of Windows security logs in Splunk. What does it mean?
Other values for app fields are :
win:remote
win:local
Thanks,
Mohammed
↧