<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help with how do I get a list of all Windows event codes that are being ingested into Splunk Ent. ? Thx a mil in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567863#M10039</link>
    <description>&lt;P&gt;Are you asking for what you have defined in inputs.conf as far as deny or do you want to find what event codes have been ingested?&lt;BR /&gt;&lt;BR /&gt;This question/answer covers the inputs entries related to denies.&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-create-more-than-10-blacklists-for-the-same-input/m-p/289583" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-create-more-than-10-blacklists-for-the-same-input/m-p/289583&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;this search should give you a breakdown of event codes with counts per code.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;index=wineventlog&lt;BR /&gt;| stats count by EventCode&lt;/P&gt;&lt;P&gt;You'll probably want to expand on that using other fields like source and Name to better understand the codes.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2021 15:31:52 GMT</pubDate>
    <dc:creator>bray1111</dc:creator>
    <dc:date>2021-09-21T15:31:52Z</dc:date>
    <item>
      <title>Please help with how do I get a list of all Windows event codes that are being ingested into Splunk Ent. ? Thx a million</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567854#M10038</link>
      <description>&lt;P&gt;How do I get a list of all Windows event codes being ingested into Splunk please?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 15:10:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567854#M10038</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-09-21T15:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with how do I get a list of all Windows event codes that are being ingested into Splunk Ent. ? Thx a mil</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567863#M10039</link>
      <description>&lt;P&gt;Are you asking for what you have defined in inputs.conf as far as deny or do you want to find what event codes have been ingested?&lt;BR /&gt;&lt;BR /&gt;This question/answer covers the inputs entries related to denies.&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-create-more-than-10-blacklists-for-the-same-input/m-p/289583" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-create-more-than-10-blacklists-for-the-same-input/m-p/289583&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;this search should give you a breakdown of event codes with counts per code.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;index=wineventlog&lt;BR /&gt;| stats count by EventCode&lt;/P&gt;&lt;P&gt;You'll probably want to expand on that using other fields like source and Name to better understand the codes.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 15:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567863#M10039</guid>
      <dc:creator>bray1111</dc:creator>
      <dc:date>2021-09-21T15:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with how do I get a list of all Windows event codes that are being ingested into Splunk Ent. ? Thx a mil</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567865#M10040</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228649"&gt;@SamHTexas&lt;/a&gt;&amp;nbsp;Use the below query after adding your index and sourcetype:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;U&gt;Run this in the smart mode and timerange for around 7 days or 30 days if possible to get the total list&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search EventCode="*" | stats count by EventCode&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 15:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Please-help-with-how-do-I-get-a-list-of-all-Windows-event-codes/m-p/567865#M10040</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-21T15:42:25Z</dc:date>
    </item>
  </channel>
</rss>

