Missing information in Event ID 4688

%3CLINGO-SUB%20id%3D%22lingo-sub-3294056%22%20slang%3D%22en-US%22%3EMissing%20information%20in%20Event%20ID%204688%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3294056%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20situation%20at%20a%20customer%20where%20they%20have%20the%20Splunk%20agent%20installed%20on%20a%20Server%202016%20Domain%20controller.%20They%20have%20enabled%20some%20advanced%20auditing%20and%20when%20retrieving%20Event%20ID%204688%20which%20is%20the%20event%20that%20records%20process%20creation%20the%20event%20details%20are%20being%20truncated.%20The%20process%20name%2C%20creater%20path%20and%20command%20line%20are%20missing.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20appears%20that%20the%20Splunk%20agent%20is%20using%20a%20deprecated%20API.%20Has%20anyone%20seen%20this%20issue%20and%20knows%20of%20a%20resolution%2Ffix..%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3294056%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EEndpoint%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3397132%22%20slang%3D%22zh-CN%22%3EReply%3A%20Missing%20information%20in%20Event%20ID%204688%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3397132%22%20slang%3D%22zh-CN%22%3EThis%20problem%20occurs%20after%20win11%20update%2022H2%2C%20and%20the%20problem%20is%20resolved%20after%20rolling%20back%2021H2%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi All

 

I have a situation at a customer where they have the Splunk agent installed on a Server 2016 Domain controller. They have enabled some advanced auditing and when retrieving Event ID 4688 which is the event that records process creation the event details are being truncated. The process name, creater path and command line are missing. 

 

It appears that the Splunk agent is using a deprecated API. Has anyone seen this issue and knows of a resolution/fix.. 

 

 

1 Reply
win11 更新22H2后出现这个问题,回退21H2后问题解决