Skip to main content
Question

Windows Events Partially ingested to secops

  • December 4, 2025
  • 1 reply
  • 20 views

bitshock1015

Hello,

Image
Image


I have a bindplane configuration that collects logs from Active Directory and Windows Events. However, I noticed that some events are not being sent to the blindplane, but are generated on the server.
For example, event 4740. I can see this event in the event viewer, but at no point is it consumed by the bindplane.

What could be causing these events not to be brought in?

1 reply

nickbebel_bindplane

Hi, I am one of the Customer Engineers at Bindplane and am taking a look at your issue.  When you are saying that you are not seeing the Events, does that mean you are not the corresponding Events on the Bindplane processor nodes or are we just not seeing it in the Destination (I’m assuming Google SecOps)?

Also, are you doing any processing of the mentioned data or are we still building out the pipeline?