There appears to be a problem with the stock windows log parser,
particularly with security message 4728. Netwitness query to find these
logs is:msg.id = 'security_4728_microsoft-windows-security-auditing' We
use this log to monitor for users added t...