I have a customer using Splunk as a SIEM to keep all the audit log. We proposed Isilon with CEE as log forwarder to Splunk. However, Isilon SMB audit log store the SID for each event, it does not contain the UserID in audit log.
Customer is looking for the way to convert SID like this:
S-1-5-21-3623811015-3361044348-30300820-1013
To Windows domain userID like this:
DOMAIN\useraccount
Is there any solution to convert the SID to UserID for Isilon audit log before we forward them to Splunk or Is there any solution to map the SID with the UserID.
I am not aware of a SID translation prior to moving to your audit server, but in investigating events, the customer can always run the following from a cluster node:
# isi auth users view --sid=
You can also look in to a translation from the audit vendor (i.e. can it connect to AD and make the translation for you.) Please let me know if there is anything else I can do for you.
johnsonka
130 Posts
2867
0
Posted October 20th, 2015 08:00
Hello sengjira,
I am not aware of a SID translation prior to moving to your audit server, but in investigating events, the customer can always run the following from a cluster node:
# isi auth users view --sid=
You can also look in to a translation from the audit vendor (i.e. can it connect to AD and make the translation for you.) Please let me know if there is anything else I can do for you.