IBM Support

Windows event ID 4776 does not update the assets with the correct identity information (APAR IJ12129)

Troubleshooting


Problem

Administrators who collect Microsoft Windows events reported an issue where event ID 4776 does not update the Windows assets with the correct identity information from the event payload. This technical note describes the identity issues related to APAR IJ12129 and how administrators can apply a workaround to resolve this asset issue.

Symptom

The most common symptom of this issue is where event ID 4776 continually updates the Windows domain controller with incorrect asset information.  The incorrect identity information causes assets to merge (vortexing) and a single Windows host accumulates IP addresses, netbios addresses, MAC addresses, and hostname information that is not associated to the correct physical appliance.
 

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000CbY6AAK","label":"QRadar-\u003EEvents-\u003EDSM Editor"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3;7.4","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
22 April 2020

UID

ibm16193437