Loading...
Windows Events

Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller

Event ID 8004 Microsoft-Windows-NTLM/Operational Network security: Restrict NTLM: Audit NTLM authentication in this domain

Main fields

IP address
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Computer name
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
User name
UserName
Windows User
ELK winlog.event_data.UserName
Microsoft Sentinel -
QRadar -
Splunk -
Important field
Not selected

Fields

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
UserName User winlog.event_data.UserName - - -
DomainName Domain winlog.event_data.DomainName - - -
IP System field IP System field - - - -
Computer System field Computer System field winlog.computer_name - - -
ProcessID System field ProcessID System field winlog.process.pid - - -
ThreadID System field ThreadID System field winlog.process.thread.id - - -

Sample Event

No Sample Event Provided.

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.