You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

257 KiB

1hostNew_Process_NamesourceEventCode
2we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
3we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
4we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
5we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
6we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
7we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
8we8105deskC:\Windows\System32\taskhost.exeWinEventLog:Security4688
9we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
10we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
11we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
12we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
13we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
14we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
15we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
16we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
17we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
18we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
19we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
20we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
21we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
22we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
23we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
24we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
25we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
26we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
27we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
28we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
29we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
30we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
31we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
32we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
33we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
34we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
35we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
36we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
37we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
38we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
39we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
40we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
41we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
42we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
43we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
44we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
45we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
46we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
47we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
48we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
49we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
50we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
51we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
52we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
53we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
54we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
55we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
56we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
57we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
58we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
59we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
60we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
61we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
62we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
63we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
64we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
65we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
66we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
67we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
68we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
69we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
70we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
71we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
72we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
73we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
74we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
75we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
76we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
77we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
78we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
79we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
80we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
81we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
82we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
83we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
84we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
85we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
86we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
87we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
88we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
89we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
90we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
91we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
92we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
93we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
94we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
95we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
96we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
97we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
98we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
99we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
100we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
101we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
102we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
103we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
104we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
105we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
106we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
107we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
108we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
109we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
110we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
111we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
112we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
113we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
114we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
115we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
116we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
117we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
118we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
119we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
120we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
121we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
122we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
123we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
124we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
125we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
126we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
127we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
128we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
129we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
130we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
131we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
132we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
133we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
134we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
135we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
136we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
137we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
138we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
139we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
140we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
141we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
142we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
143we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
144we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
145we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
146we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
147we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
148we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
149we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
150we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
151we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
152we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
153we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
154we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
155we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
156we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
157we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
158we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
159we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
160we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
161we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
162we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
163we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
164we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
165we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
166we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
167we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
168we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
169we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
170we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
171we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
172we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
173we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
174we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
175we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
176we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
177we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
178we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
179we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
180we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
181we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
182we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
183we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
184we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
185we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
186we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
187we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
188we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
189we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
190we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
191we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
192we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
193we8105deskC:\Windows\System32\w32tm.exeWinEventLog:Security4688
194we8105deskC:\Windows\System32\PING.EXEWinEventLog:Security4688
195we8105deskC:\Windows\System32\w32tm.exeWinEventLog:Security4688
196we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exeWinEventLog:Security4688
197we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exeWinEventLog:Security4688
198we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
199we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exeWinEventLog:Security4688
200we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exeWinEventLog:Security4688
201we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exeWinEventLog:Security4688
202we8105deskC:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exeWinEventLog:Security4688
203we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
204we8105deskC:\Windows\System32\sdiagnhost.exeWinEventLog:Security4688
205we8105deskC:\Windows\System32\svchost.exeWinEventLog:Security4688
206we8105deskC:\Windows\System32\taskhost.exeWinEventLog:Security4688
207we8105deskC:\Windows\System32\VSSVC.exeWinEventLog:Security4688
208we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
209we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
210we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
211we8105deskC:\Windows\System32\mcbuilder.exeWinEventLog:Security4688
212we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
213we8105deskC:\Windows\System32\rundll32.exeWinEventLog:Security4688
214we8105deskC:\Windows\System32\lpremove.exeWinEventLog:Security4688
215we8105deskC:\Windows\System32\rundll32.exeWinEventLog:Security4688
216we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
217we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
218we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
219we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
220we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
221we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
222we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
223we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
224we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
225we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
226we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
227we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
228we1149srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
229we1149srvC:\Windows\System32\sc.exeWinEventLog:Security4688
230we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
231we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
232we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
233we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
234we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
235we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
236we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
237we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
238we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
239we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
240we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
241we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
242we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
243we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
244we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
245we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
246we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
247we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
248we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
249we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
250we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
251we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
252we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
253we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
254we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
255we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
256we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
257we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
258we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
259we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
260we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
261we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
262we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
263we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
264we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
265we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
266we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
267we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
268we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
269we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
270we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
271we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
272we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
273we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
274we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
275we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
276we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
277we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
278we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
279we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
280we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
281we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
282we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
283we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
284we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
285we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
286we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
287we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
288we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
289we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
290we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
291we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
292we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
293we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
294we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
295we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
296we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
297we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
298we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
299we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
300we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
301we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
302we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
303we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
304we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
305we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
306we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
307we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
308we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
309we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
310we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
311we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
312we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
313we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
314we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
315we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
316we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
317we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
318we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
319we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
320we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
321we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
322we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
323we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
324we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
325we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
326we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
327we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
328we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
329we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
330we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
331we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
332we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
333we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
334we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
335we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
336we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
337we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
338we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
339we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
340we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
341we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
342we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
343we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
344we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
345we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
346we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
347we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
348we8105deskC:\Windows\System32\svchost.exeWinEventLog:Security4688
349we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
350we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
351we8105deskC:\Windows\System32\taskhost.exeWinEventLog:Security4688
352we8105deskC:\Windows\System32\Defrag.exeWinEventLog:Security4688
353we8105deskC:\Windows\System32\aitagent.exeWinEventLog:Security4688
354we8105deskC:\Windows\System32\rundll32.exeWinEventLog:Security4688
355we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
356we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
357we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
358we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
359we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
360we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
361we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
362we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
363we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
364we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
365we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
366we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
367we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
368we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
369we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
370we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
371we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
372we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
373we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
374we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
375we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
376we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
377we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
378we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
379we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
380we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
381we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
382we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
383we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
384we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
385we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
386we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
387we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
388we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
389we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
390we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
391we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
392we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
393we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
394we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
395we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
396we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
397we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
398we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
399we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
400we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
401we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
402we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
403we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
404we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
405we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
406we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
407we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
408we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
409we8105deskC:\Windows\System32\taskhost.exeWinEventLog:Security4688
410we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
411we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
412we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
413we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
414we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
415we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
416we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
417we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
418we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
419we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
420we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
421we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
422we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
423we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
424we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
425we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
426we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
427we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
428we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
429we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
430we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
431we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
432we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
433we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
434we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
435we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
436we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
437we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
438we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
439we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
440we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
441we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
442we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
443we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
444we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
445we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
446we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
447we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
448we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
449we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
450we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
451we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
452we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
453we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
454we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
455we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
456we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
457we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
458we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
459we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
460we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
461we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
462we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
463we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
464we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
465we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
466we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
467we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
468we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
469we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
470we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
471we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
472we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
473we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
474we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
475we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
476we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
477we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
478we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
479we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
480we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
481we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
482we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
483we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
484we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
485we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
486we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
487we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
488we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
489we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
490we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
491we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
492we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
493we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
494we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
495we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
496we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
497we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
498we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
499we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
500we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
501we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
502we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
503we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
504we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
505we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
506we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
507we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
508we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
509we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
510we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
511we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
512we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
513we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
514we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
515we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
516we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
517we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
518we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
519we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
520we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
521we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
522we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
523we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
524we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
525we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
526we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
527we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
528we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
529we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
530we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
531we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
532we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
533we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
534we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
535we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
536we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
537we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
538we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
539we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
540we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
541we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
542we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
543we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
544we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
545we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
546we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
547we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
548we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
549we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
550we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
551we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
552we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
553we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
554we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
555we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
556we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
557we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
558we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
559we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
560we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
561we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
562we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
563we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
564we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
565we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
566we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
567we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
568we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
569we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
570we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
571we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
572we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
573we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
574we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
575we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
576we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
577we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
578we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
579we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
580we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
581we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
582we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
583we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
584we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
585we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
586we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
587we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
588we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
589we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
590we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
591we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
592we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
593we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
594we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
595we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
596we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
597we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
598we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
599we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
600we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
601we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
602we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
603we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
604we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
605we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
606we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
607we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
608we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
609we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
610we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
611we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
612we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
613we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
614we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
615we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
616we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
617we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
618we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
619we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
620we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
621we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
622we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
623we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
624we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
625we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
626we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
627we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
628we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
629we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
630we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
631we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
632we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
633we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
634we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
635we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
636we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
637we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
638we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
639we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
640we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
641we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
642we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
643we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
644we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
645we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
646we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
647we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
648we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
649we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
650we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
651we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
652we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
653we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
654we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
655we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
656we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
657we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
658we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
659we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
660we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
661we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
662we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
663we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
664we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
665we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
666we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
667we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
668we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
669we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
670we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
671we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
672we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
673we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
674we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
675we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
676we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
677we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
678we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
679we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
680we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
681we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
682we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
683we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
684we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
685we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
686we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
687we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
688we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
689we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
690we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
691we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
692we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
693we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
694we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
695we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
696we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
697we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
698we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
699we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
700we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
701we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
702we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
703we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
704we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
705we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
706we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
707we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
708we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
709we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
710we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
711we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
712we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
713we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
714we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
715we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
716we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
717we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
718we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
719we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
720we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
721we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
722we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
723we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
724we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
725we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
726we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
727we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
728we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
729we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
730we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
731we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
732we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
733we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
734we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
735we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
736we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
737we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
738we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
739we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
740we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
741we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
742we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
743we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
744we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
745we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
746we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
747we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
748we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
749we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
750we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
751we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
752we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
753we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
754we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
755we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
756we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
757we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
758we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
759we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
760we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
761we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
762we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
763we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
764we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
765we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
766we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
767we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
768we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
769we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
770we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
771we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
772we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
773we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
774we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
775we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
776we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
777we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
778we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
779we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
780we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
781we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
782we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
783we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
784we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
785we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
786we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
787we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
788we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
789we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
790we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
791we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
792we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
793we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
794we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
795we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
796we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
797we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
798we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
799we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
800we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
801we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
802we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
803we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
804we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
805we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
806we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
807we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
808we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
809we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
810we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
811we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
812we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
813we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
814we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
815we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
816we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
817we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
818we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
819we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
820we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
821we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
822we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
823we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
824we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
825we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
826we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
827we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
828we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
829we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
830we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
831we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
832we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
833we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
834we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
835we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
836we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
837we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
838we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
839we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
840we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
841we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
842we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
843we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
844we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
845we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
846we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
847we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
848we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
849we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
850we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
851we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
852we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
853we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
854we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
855we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
856we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
857we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
858we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
859we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
860we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
861we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
862we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
863we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
864we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
865we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
866we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
867we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
868we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
869we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
870we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
871we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
872we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
873we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
874we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
875we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
876we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
877we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
878we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
879we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
880we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
881we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
882we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
883we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
884we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
885we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
886we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
887we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
888we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
889we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
890we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
891we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
892we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
893we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
894we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
895we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
896we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
897we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
898we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
899we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
900we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
901we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
902we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
903we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
904we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
905we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
906we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
907we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
908we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
909we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
910we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
911we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
912we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
913we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
914we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
915we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
916we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
917we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
918we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
919we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
920we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
921we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
922we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
923we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
924we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
925we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
926we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
927we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
928we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
929we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
930we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
931we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
932we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
933we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
934we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
935we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
936we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
937we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
938we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
939we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
940we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
941we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
942we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
943we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
944we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
945we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
946we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
947we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
948we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
949we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
950we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
951we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
952we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
953we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
954we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
955we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
956we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
957we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
958we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
959we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
960we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
961we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
962we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
963we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
964we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
965we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
966we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
967we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
968we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
969we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
970we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
971we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
972we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
973we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
974we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
975we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
976we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
977we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
978we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
979we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
980we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
981we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
982we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
983we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
984we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
985we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
986we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
987we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
988we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
989we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
990we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
991we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
992we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
993we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
994we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
995we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
996we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
997we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
998we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
999we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1000we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1001we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1002we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1003we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1004we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1005we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1006we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1007we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1008we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1009we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1010we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1011we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1012we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1013we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1014we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1015we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1016we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1017we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1018we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1019we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1020we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1021we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1022we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1023we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1024we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1025we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1026we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1027we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1028we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1029we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1030we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1031we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1032we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1033we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1034we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1035we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1036we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1037we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1038we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1039we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1040we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1041we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1042we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1043we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1044we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1045we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1046we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1047we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1048we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1049we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1050we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1051we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1052we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1053we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1054we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1055we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1056we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1057we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1058we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1059we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1060we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1061we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1062we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1063we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1064we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1065we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1066we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1067we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1068we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1069we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1070we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1071we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1072we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1073we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1074we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1075we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1076we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1077we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1078we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1079we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1080we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1081we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1082we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1083we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1084we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1085we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1086we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1087we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1088we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1089we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1090we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1091we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1092we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1093we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1094we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1095we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1096we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1097we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1098we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1099we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1100we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1101we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1102we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1103we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1104we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1105we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1106we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1107we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1108we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1109we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1110we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1111we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1112we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1113we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1114we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1115we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1116we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1117we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1118we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1119we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1120we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1121we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1122we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1123we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1124we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1125we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1126we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1127we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1128we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1129we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1130we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1131we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1132we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1133we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1134we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1135we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1136we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1137we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1138we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1139we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1140we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1141we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1142we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1143we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1144we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1145we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1146we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1147we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1148we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1149we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1150we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1151we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1152we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1153we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1154we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1155we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1156we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1157we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1158we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1159we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1160we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1161we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1162we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1163we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1164we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1165we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1166we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1167we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1168we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1169we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1170we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1171we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1172we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1173we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1174we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1175we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1176we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1177we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1178we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1179we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1180we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1181we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1182we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1183we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1184we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1185we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1186we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1187we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1188we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1189we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1190we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1191we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1192we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1193we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1194we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1195we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1196we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1197we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1198we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1199we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1200we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1201we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1202we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1203we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1204we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1205we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1206we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1207we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1208we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1209we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1210we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1211we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1212we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1213we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1214we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1215we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1216we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1217we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1218we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1219we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1220we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1221we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1222we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1223we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1224we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1225we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1226we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1227we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1228we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1229we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1230we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1231we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1232we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1233we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1234we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1235we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1236we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1237we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1238we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1239we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1240we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1241we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1242we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1243we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1244we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1245we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1246we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1247we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1248we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1249we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1250we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1251we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1252we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1253we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1254we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1255we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1256we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1257we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1258we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1259we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1260we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1261we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1262we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1263we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1264we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1265we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1266we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1267we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1268we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1269we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1270we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1271we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1272we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1273we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1274we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1275we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1276we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1277we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1278we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1279we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1280we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1281we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1282we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1283we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1284we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1285we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1286we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1287we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1288we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1289we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1290we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1291we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1292we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1293we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1294we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1295we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1296we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1297we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1298we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1299we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1300we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1301we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1302we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1303we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1304we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1305we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1306we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1307we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1308we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1309we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1310we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1311we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1312we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1313we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1314we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1315we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1316we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1317we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1318we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1319we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1320we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1321we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1322we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1323we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1324we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1325we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1326we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1327we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1328we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1329we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1330we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1331we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1332we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1333we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1334we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1335we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1336we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1337we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1338we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1339we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1340we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1341we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1342we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1343we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1344we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1345we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1346we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1347we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1348we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1349we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1350we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1351we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1352we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1353we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1354we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1355we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1356we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1357we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1358we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1359we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1360we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1361we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1362we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1363we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1364we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1365we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1366we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1367we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1368we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1369we8105deskC:\Windows\System32\PING.EXEWinEventLog:Security4688
1370we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1371we8105deskC:\Windows\System32\taskkill.exeWinEventLog:Security4688
1372we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1373we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
1374we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1375we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1376we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1377we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1378we8105deskC:\Windows\System32\wscript.exeWinEventLog:Security4688
1379we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1380we8105deskC:\Program Files (x86)\Internet Explorer\iexplore.exeWinEventLog:Security4688
1381we8105deskC:\Windows\System32\notepad.exeWinEventLog:Security4688
1382we8105deskC:\Program Files (x86)\Internet Explorer\iexplore.exeWinEventLog:Security4688
1383we8105deskC:\Program Files (x86)\Internet Explorer\iexplore.exeWinEventLog:Security4688
1384we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1385we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1386we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1387we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1388we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1389we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1390we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1391we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1392we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1393we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1394we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1395we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1396we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1397we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1398we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1399we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1400we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1401we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1402we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1403we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1404we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1405we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1406we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1407we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1408we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1409we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1410we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1411we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1412we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1413we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1414we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1415we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1416we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1417we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1418we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1419we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1420we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1421we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1422we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1423we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1424we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1425we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1426we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1427we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1428we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1429we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1430we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1431we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1432we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1433we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1434we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1435we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1436we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1437we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1438we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1439we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1440we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1441we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1442we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1443we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1444we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1445we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1446we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1447we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1448we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1449we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1450we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1451we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1452we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1453we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1454we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1455we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1456we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1457we8105deskC:\Windows\explorer.exeWinEventLog:Security4688
1458we8105deskC:\Windows\System32\taskhost.exeWinEventLog:Security4688
1459we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1460we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1461we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1462we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1463we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1464we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1465we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1466we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1467we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1468we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1469we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1470we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1471we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1472we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1473we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1474we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1475we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1476we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1477we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1478we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1479we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1480we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1481we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1482we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1483we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1484we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1485we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1486we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1487we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1488we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1489we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1490we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1491we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1492we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1493we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1494we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1495we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1496we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1497we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1498we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1499we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1500we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1501we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1502we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1503we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1504we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1505we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1506we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1507we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1508we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1509we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1510we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1511we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1512we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1513we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1514we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1515we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1516we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1517we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1518we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1519we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1520we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1521we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1522we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1523we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1524we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1525we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1526we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1527we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1528we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1529we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1530we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1531we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1532we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1533we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1534we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1535we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1536we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1537we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1538we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1539we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1540we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1541we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1542we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1543we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1544we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1545we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1546we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1547we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1548we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1549we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1550we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1551we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1552we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1553we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1554we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1555we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1556we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1557we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1558we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1559we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1560we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1561we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1562we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1563we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1564we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1565we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1566we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1567we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1568we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1569we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1570we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1571we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1572we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1573we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1574we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1575we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1576we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1577we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1578we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1579we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1580we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1581we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1582we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1583we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1584we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1585we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1586we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1587we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1588we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1589we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1590we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1591we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1592we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1593we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1594we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1595we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1596we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1597we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1598we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1599we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1600we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1601we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1602we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1603we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1604we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1605we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1606we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1607we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1608we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1609we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1610we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1611we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1612we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1613we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1614we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1615we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1616we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1617we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1618we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1619we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1620we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1621we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1622we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1623we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1624we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1625we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1626we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1627we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1628we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1629we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1630we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1631we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1632we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1633we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1634we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1635we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1636we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1637we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1638we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1639we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1640we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1641we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1642we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1643we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1644we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1645we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1646we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1647we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1648we8105deskC:\Windows\System32\audiodg.exeWinEventLog:Security4688
1649we8105deskC:\Windows\System32\rundll32.exeWinEventLog:Security4688
1650we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1651we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1652we8105deskC:\Windows\System32\DeviceDisplayObjectProvider.exeWinEventLog:Security4688
1653we8105deskC:\Windows\System32\DeviceDisplayObjectProvider.exeWinEventLog:Security4688
1654we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1655we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1656we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1657we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1658we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1659we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1660we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1661we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1662we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1663we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1664we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1665we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1666we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1667we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1668we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1669we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1670we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1671we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1672we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1673we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1674we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1675we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1676we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1677we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1678we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1679we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1680we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1681we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1682we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1683we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1684we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1685we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1686we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1687we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1688we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1689we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1690we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1691we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1692we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1693we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1694we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1695we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1696we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1697we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1698we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1699we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1700we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1701we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1702we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1703we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1704we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1705we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1706we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1707we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1708we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1709we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1710we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1711we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1712we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1713we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1714we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1715we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1716we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1717we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1718we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1719we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1720we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1721we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1722we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1723we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1724we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1725we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1726we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1727we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1728we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1729we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1730we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1731we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1732we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1733we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1734we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1735we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1736we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1737we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1738we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1739we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1740we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1741we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1742we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1743we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1744we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1745we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1746we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1747we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1748we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1749we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1750we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1751we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1752we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1753we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1754we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1755we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1756we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1757we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1758we8105deskC:\Program Files (x86)\Internet Explorer\iexplore.exeWinEventLog:Security4688
1759we8105deskC:\Program Files (x86)\Internet Explorer\iexplore.exeWinEventLog:Security4688
1760we8105deskC:\Windows\System32\rundll32.exeWinEventLog:Security4688
1761we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1762we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1763we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1764we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1765we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1766we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1767we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1768we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1769we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1770we8105deskC:\Windows\explorer.exeWinEventLog:Security4688
1771we8105deskC:\Windows\System32\audiodg.exeWinEventLog:Security4688
1772we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1773we8105deskC:\Windows\explorer.exeWinEventLog:Security4688
1774we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1775we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1776we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1777we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1778we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1779we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1780we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1781we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1782we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1783we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1784we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1785we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1786we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1787we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1788we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1789we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1790we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1791we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1792we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1793we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1794we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1795we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1796we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1797we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1798we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1799we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1800we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1801we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1802we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1803we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1804we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1805we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1806we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1807we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1808we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1809we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1810we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1811we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1812we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1813we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1814we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1815we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1816we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1817we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1818we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1819we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1820we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1821we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1822we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1823we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1824we8105deskC:\Windows\System32\slui.exeWinEventLog:Security4688
1825we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1826we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1827we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1828we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1829we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1830we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1831we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1832we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1833we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1834we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1835we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1836we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1837we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1838we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1839we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1840we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1841we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1842we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1843we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1844we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1845we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1846we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1847we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1848we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1849we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1850we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1851we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1852we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1853we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1854we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1855we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1856we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1857we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1858we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1859we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1860we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1861we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1862we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1863we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1864we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1865we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1866we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1867we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
1868we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1869we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1870we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1871we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1872we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1873we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1874we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1875we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1876we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1877we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1878we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1879we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1880we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1881we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1882we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1883we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1884we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1885we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1886we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1887we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1888we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1889we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1890we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1891we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1892we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1893we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1894we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1895we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1896we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1897we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1898we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1899we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
1900we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
1901we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1902we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1903we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1904we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1905we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1906we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1907we8105deskC:\Windows\System32\bcdedit.exeWinEventLog:Security4688
1908we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1909we8105deskC:\Windows\System32\bcdedit.exeWinEventLog:Security4688
1910we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1911we8105deskC:\Windows\System32\wbem\WMIC.exeWinEventLog:Security4688
1912we8105deskC:\Windows\System32\svchost.exeWinEventLog:Security4688
1913we8105deskC:\Windows\System32\VSSVC.exeWinEventLog:Security4688
1914we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1915we8105deskC:\Windows\System32\vssadmin.exeWinEventLog:Security4688
1916we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1917we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1918we8105deskC:\Windows\System32\consent.exeWinEventLog:Security4688
1919we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\{35ACA89F-933F-6A5D-2776-A3589FB99832}\osk.exeWinEventLog:Security4688
1920we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\{35ACA89F-933F-6A5D-2776-A3589FB99832}\osk.exeWinEventLog:Security4688
1921we8105deskC:\Windows\SysWOW64\QqJXZrBKCk72XzRgZs\AdapterTroubleshooter.exeWinEventLog:Security4688
1922we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1923we8105deskC:\Windows\System32\consent.exeWinEventLog:Security4688
1924we8105deskC:\Windows\SysWOW64\QqJXZrBKCk72XzRgZs\AdapterTroubleshooter.exeWinEventLog:Security4688
1925we8105deskC:\Windows\System32\consent.exeWinEventLog:Security4688
1926we8105deskC:\Windows\System32\consent.exeWinEventLog:Security4688
1927we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
1928we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
1929we8105deskC:\Windows\System32\consent.exeWinEventLog:Security4688
1930we8105deskC:\Windows\SysWOW64\explorer.exeWinEventLog:Security4688
1931we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1932we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1933we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1934we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1935we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1936we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1937we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1938we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1939we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1940we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1941we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1942we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1943we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\{35ACA89F-933F-6A5D-2776-A3589FB99832}\osk.exeWinEventLog:Security4688
1944we8105deskC:\Windows\SysWOW64\PING.EXEWinEventLog:Security4688
1945we8105deskC:\Windows\SysWOW64\taskkill.exeWinEventLog:Security4688
1946we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1947we8105deskC:\Windows\SysWOW64\cmd.exeWinEventLog:Security4688
1948we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\{35ACA89F-933F-6A5D-2776-A3589FB99832}\osk.exeWinEventLog:Security4688
1949we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1950we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1951we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1952we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1953we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1954we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1955we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\121214.tmpWinEventLog:Security4688
1956we8105deskC:\Users\bob.smith.WAYNECORPINC\AppData\Roaming\121214.tmpWinEventLog:Security4688
1957we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
1958we8105deskC:\Windows\SysWOW64\cmd.exeWinEventLog:Security4688
1959we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1960we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1961we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1962we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1963we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1964we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1965we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1966we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1967we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1968we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1969we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1970we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1971we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1972we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1973we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1974we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1975we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1976we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1977we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1978we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1979we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1980we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1981we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1982we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1983we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1984we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1985we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1986we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1987we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1988we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1989we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1990we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1991we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1992we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1993we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
1994we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1995we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
1996we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
1997we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
1998we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
1999we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2000we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2001we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2002we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2003we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2004we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2005we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2006we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2007we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2008we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2009we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2010we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2011we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2012we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2013we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2014we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2015we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2016we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2017we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2018we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2019we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2020we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2021we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2022we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2023we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2024we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2025we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2026we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2027we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2028we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2029we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2030we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2031we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2032we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2033we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
2034we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
2035we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
2036we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2037we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2038we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2039we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2040we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2041we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2042we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2043we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2044we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2045we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2046we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2047we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2048we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
2049we8105deskC:\Windows\explorer.exeWinEventLog:Security4688
2050we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2051we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2052we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2053we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2054we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2055we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2056we8105deskC:\Windows\splwow64.exeWinEventLog:Security4688
2057we8105deskC:\Windows\SysWOW64\wscript.exeWinEventLog:Security4688
2058we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2059we8105deskC:\Windows\SysWOW64\cmd.exeWinEventLog:Security4688
2060we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
2061we8105deskC:\Windows\System32\wbem\WMIADAP.exeWinEventLog:Security4688
2062we8105deskC:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXEWinEventLog:Security4688
2063we8105deskC:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXEWinEventLog:Security4688
2064we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
2065we8105deskC:\Windows\System32\dllhost.exeWinEventLog:Security4688
2066we8105deskC:\Windows\SysWOW64\dllhost.exeWinEventLog:Security4688
2067we8105deskC:\Windows\explorer.exeWinEventLog:Security4688
2068we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2069we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2070we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2071we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2072we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2073we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2074we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2075we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2076we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2077we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2078we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2079we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2080we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2081we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2082we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2083we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2084we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2085we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2086we8105deskC:\Windows\System32\audiodg.exeWinEventLog:Security4688
2087we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2088we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2089we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2090we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2091we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2092we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2093we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2094we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2095we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2096we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2097we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2098we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2099we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2100we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2101we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2102we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2103we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2104we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2105we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2106we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2107we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2108we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2109we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2110we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2111we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2112we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2113we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2114we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2115we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2116we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2117we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2118we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2119we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2120we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2121we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2122we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2123we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2124we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2125we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2126we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2127we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2128we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2129we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2130we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2131we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2132we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2133we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2134we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2135we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2136we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2137we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2138we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2139we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2140we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2141we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2142we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2143we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2144we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2145we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2146we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2147we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2148we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2149we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2150we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2151we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2152we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2153we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2154we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2155we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2156we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2157we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2158we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2159we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2160we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2161we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2162we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2163we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2164we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2165we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2166we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2167we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2168we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2169we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2170we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2171we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2172we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2173we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2174we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2175we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2176we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2177we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2178we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2179we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2180we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2181we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2182we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2183we9041srvC:\Windows\System32\dwm.exeWinEventLog:Security4688
2184we9041srvC:\Windows\System32\LogonUI.exeWinEventLog:Security4688
2185we9041srvC:\Windows\System32\winlogon.exeWinEventLog:Security4688
2186we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2187we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2188we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2189we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2190we9041srvC:\Windows\System32\csrss.exeWinEventLog:Security4688
2191we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2192we9041srvC:\Windows\System32\smss.exeWinEventLog:Security4688
2193we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2194we8105deskC:\Windows\System32\choice.exeWinEventLog:Security4688
2195we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2196we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2197we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2198we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2199we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2200we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2201we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2202we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2203we1149srvC:\Windows\System32\dwm.exeWinEventLog:Security4688
2204we1149srvC:\Windows\System32\LogonUI.exeWinEventLog:Security4688
2205we1149srvC:\Windows\System32\winlogon.exeWinEventLog:Security4688
2206we1149srvC:\Windows\System32\csrss.exeWinEventLog:Security4688
2207we1149srvC:\Windows\System32\smss.exeWinEventLog:Security4688
2208we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
2209we8105deskC:\Windows\tenable_mw_scan_142a90001fb65e0beb1751cc8c63edd0.exeWinEventLog:Security4688
2210we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2211we8105deskC:\Windows\System32\sc.exeWinEventLog:Security4688
2212we9041srvC:\Windows\System32\choice.exeWinEventLog:Security4688
2213we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2214we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2215we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2216we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2217we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2218we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2219we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2220we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2221we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2222we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2223we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2224we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2225we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2226we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2227we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2228we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2229we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2230we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2231we8105deskC:\Windows\System32\schtasks.exeWinEventLog:Security4688
2232we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2233we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2234we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2235we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2236we9041srvC:\Windows\tenable_mw_scan_142a90001fb65e0beb1751cc8c63edd0.exeWinEventLog:Security4688
2237we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2238we9041srvC:\Windows\System32\sc.exeWinEventLog:Security4688
2239we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2240we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2241we9041srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2242we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2243we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2244we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2245we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2246we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2247we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2248we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2249we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2250we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2251we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2252we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2253we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2254we8105deskC:\Windows\System32\netsh.exeWinEventLog:Security4688
2255we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2256we8105deskC:\Windows\System32\netsh.exeWinEventLog:Security4688
2257we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2258we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2259we9041srvC:\Windows\System32\schtasks.exeWinEventLog:Security4688
2260we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2261we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2262we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2263we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2264we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2265we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2266we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2267we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2268we8105deskC:\Windows\System32\tasklist.exeWinEventLog:Security4688
2269we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2270we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2271we9041srvC:\Windows\System32\svchost.exeWinEventLog:Security4688
2272we9041srvC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWinEventLog:Security4688
2273we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2274we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2275we9041srvC:\Windows\System32\netsh.exeWinEventLog:Security4688
2276we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2277we9041srvC:\Windows\System32\netsh.exeWinEventLog:Security4688
2278we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2279we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2280we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2281we8105deskC:\Windows\System32\svchost.exeWinEventLog:Security4688
2282we8105deskC:\Windows\System32\netsh.exeWinEventLog:Security4688
2283we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2284we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2285we8105deskC:\Windows\servicing\TrustedInstaller.exeWinEventLog:Security4688
2286we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2287we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2288we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2289we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2290we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2291we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2292we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2293we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2294we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2295we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2296we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2297we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2298we8105deskC:\Windows\System32\NETSTAT.EXEWinEventLog:Security4688
2299we8105deskC:\Windows\System32\SearchFilterHost.exeWinEventLog:Security4688
2300we8105deskC:\Windows\System32\conhost.exeWinEventLog:Security4688
2301we8105deskC:\Windows\System32\SearchProtocolHost.exeWinEventLog:Security4688
2302we8105deskC:\Windows\System32\cmd.exeWinEventLog:Security4688
2303we8105deskC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2304we1149srvC:\Windows\System32\inetsrv\w3wp.exeWinEventLog:Security4688
2305we9041srvC:\Windows\System32\tasklist.exeWinEventLog:Security4688
2306we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2307we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2308we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2309we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2310we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2311we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2312we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2313we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2314we9041srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2315we9041srvC:\Windows\System32\netsh.exeWinEventLog:Security4688
2316we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2317we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2318we9041srvC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.16384_none_fa1dc1539b4180d8\TiWorker.exeWinEventLog:Security4688
2319we9041srvC:\Windows\servicing\TrustedInstaller.exeWinEventLog:Security4688
2320we9041srvC:\Windows\System32\sppsvc.exeWinEventLog:Security4688
2321we9041srvC:\Windows\System32\NETSTAT.EXEWinEventLog:Security4688
2322we9041srvC:\Windows\System32\conhost.exeWinEventLog:Security4688
2323we9041srvC:\Windows\System32\cmd.exeWinEventLog:Security4688
2324we9041srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2325we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2326we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2327we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2328we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2329we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2330we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2331we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2332we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2333we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2334we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2335we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2336we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2337we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2338we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2339we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2340we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2341we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2342we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2343we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2344we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2345we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2346we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2347we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2348we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2349we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2350we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2351we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2352we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2353we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2354we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2355we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2356we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2357we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2358we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2359we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2360we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2361we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2362we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2363we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2364we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2365we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2366we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2367we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2368we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2369we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2370we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2371we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2372we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2373we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2374we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2375we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2376we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2377we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2378we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2379we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2380we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2381we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2382we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2383we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2384we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2385we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2386we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2387we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2388we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2389we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2390we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2391we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2392we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2393we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2394we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2395we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2396we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2397we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2398we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2399we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2400we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2401we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2402we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2403we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2404we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2405we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2406we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2407we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2408we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2409we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2410we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2411we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2412we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2413we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2414we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2415we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2416we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2417we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2418we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2419we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2420we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2421we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2422we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2423we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2424we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2425we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2426we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2427we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2428we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2429we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2430we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2431we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2432we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2433we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2434we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2435we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2436we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2437we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2438we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2439we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2440we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2441we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2442we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2443we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2444we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2445we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2446we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2447we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2448we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2449we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2450we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2451we9041srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2452we9041srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2453we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2454we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2455we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2456we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2457we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2458we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2459we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2460we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2461we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2462we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2463we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2464we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2465we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2466we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2467we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2468we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2469we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2470we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2471we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2472we1149srvC:\Windows\System32\wbem\WmiPrvSE.exeWinEventLog:Security4688
2473we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2474we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2475we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2476we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2477we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2478we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2479we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2480we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2481we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2482we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2483we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2484we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2485we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2486we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2487we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2488we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2489we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2490we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2491we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2492we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2493we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2494we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2495we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2496we9041srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2497we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2498we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2499we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2500we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2501we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2502we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2503we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2504we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688
2505we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2506we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2507we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2508we1149srvC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2509we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exeWinEventLog:Security4688
2510we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exeWinEventLog:Security4688
2511we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2512we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exeWinEventLog:Security4688
2513we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exeWinEventLog:Security4688
2514we8105deskC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exeWinEventLog:Security4688