2015-06-21 08:07 AM
Dears,
I am facing a problem with windows events,
i am getting in the event a field called parsererror: EVENTTIME
how can i solve this?
Microsoft event ID = 4738
2015-06-24 04:57 AM
looking at the parser xml file entry below, I think the colored parts is causing this error.
a quick guess is that the account expire field is empty or format is not correct
does the parser error appear twice?
can you share sample logs?
<HEADER
id1="0004"
id2="0004"
messageid="STRCAT(msgIdPart1, '_', msgIdPart2, '_', 'Microsoft-Windows-Security-Auditing')"
content="%NICWIN-<hlevel>-<Hmessageid>: <msgIdPart1>,<Hlinenum>,<Hday> <Hdatetime>,<msgIdPart2>,Microsoft-Windows-Security-Auditing,<Hevent_user>,<Hevent_type>,<Hevent_computer>,<Hcategory>,<Hdata>,<!payload>"/>
<MESSAGE
level="6"
parse="1"
parsedefvalue="1"
tableid="85"
id1="Security_4738_Microsoft-Windows-Security-Auditing:01"
id2="Security_4738_Microsoft-Windows-Security-Auditing"
eventcategory="1402020300"
summary="NIC_B_WINDOWS;sumtype=11;|NIC_B_WINDOWS;key=event_computer;sumtype=12;|NIC_B_WINDOWS;key=event_type;sumtype=13;|NIC_B_WINDOWS;key=category;sumtype=14;|NIC_B_CATEGORIES;sumtype=denied_in;|NIC_B_CATEGORIES;subkey=event_log;sumtype=connection;"
content="<@ec_theme:UserGroup><@ec_subject:User><@ec_activity:Modify><@ec_outcome:Success><@:*SYSVAL($MSGID,$ID1)><@msg:*PARMVAL($MSG)><@event_log:*HDR(msgIdPart1)><@expiration_time:*EVNTTIME($MSG,'%G/%F/%W %N:%U:%O %P',fld8)><@event_time:*EVNTTIME($HDR,'%B %F %H:%U:%O %W',Hdatetime)><@id:*HDR(msgIdPart2)><@event_source:Microsoft-Windows-Security-Auditing><@event_type:*HDR(Hevent_type)><@event_user:*HDR(Hevent_user)><@event_computer:*HDR(Hevent_computer)><@category:*HDR(Hcategory)><@fld61:*PARMVAL(username)><@fld63:*PARMVAL(domain)><event_description> Subject: Security ID: <sid> Account Name: <username> Account Domain: <domain> Logon ID: <sessionid> Target Account: Security ID: <fld39> Account Name: <c_username> Account Domain: <c_domain> Changed Attributes: <space> SAM Account Name: <user_fullname> Display Name: <param> Password Last Set: <fld7> Account Expires: <fld8> Primary Group ID: <groupid> AllowedToDelegateTo: <fld88> Old UAC Value: <change_old> New UAC Value: <change_new> User Account Control: <fld87> Additional Information: Privileges <privilege>" />