Hi,
I think AD parser need an enhancement. It should parser "Service Name" from event "A Kerberos service ticket was requested". Usually that field contains an account name, that can be used to track authentications. Now that is not parsed at all.

We have an customer use-case and this is needed urgently.

Comments