Microsoft Windows RC4 Cipher Retirement (for Kerberos)
Assuming you have your Microsoft Windows Domain Controllers sending their event logs into Splunk, here is a query that will pull out the pertinent details you need to find anything that is still running non-compliant RC4 for ticketing. Note that your index and Log names may vary.