I'm trying to alert on software install events, but the events are showing the user as "NOT_TRANSLATED". I get a SID, but that isn't helpful for alerting. I have a distributed SPLUNK install (not sure if that matters). How do I get the user name info translated for the events?
↧