<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 4688 event code to be excluded from universal forwarder directory path alone in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/740999#M21796</link>
    <description>&lt;P&gt;Tried below regex to blacklist OR ignore 4688 event codes from the *.exe coming from the splunk forwarder path/directory&lt;/P&gt;&lt;P&gt;But not working, it's considering 4688 from splunk and non-splunk path&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;not sending events from both splunk and non-splunk path.&lt;/P&gt;&lt;P&gt;Looking for a regex to be added as blacklist to ignore 4688 coming from *.exe files part of splunk universal forwarder path/directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?i)(?:[C-F]:\Program Files\Splunk(?:UniversalForwarder)?\bin\(?:btool|splunkd|splunk|splunk-(?:MonitorNoHandle|admon|netmon|perfmon|powershell|regmon|winevtlog|winhostinfo|winprintmon|wmi)).exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?:[a-zA-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.+\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?:[a-zA-Z]:\\\\Program Files\\\\Splunk(?:\\\\UniversalForwarder)?\\\\bin\\\\.+\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: C:\\\\Program Files\\\\SplunkUniversalForwarder\\\\bin\\\\"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: C:\\Program Files\\SplunkUniversalForwarder\\bin\\"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?i)[A-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.*\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name:\s*[A-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.+\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name:\s*[A-Z]:\\\\Program Files\\\\SplunkUniversalForwarder\\\\bin\\\\.*\\.exe"&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 08:43:37 GMT</pubDate>
    <dc:creator>sureshkumaar</dc:creator>
    <dc:date>2025-03-06T08:43:37Z</dc:date>
    <item>
      <title>4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/740999#M21796</link>
      <description>&lt;P&gt;Tried below regex to blacklist OR ignore 4688 event codes from the *.exe coming from the splunk forwarder path/directory&lt;/P&gt;&lt;P&gt;But not working, it's considering 4688 from splunk and non-splunk path&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;not sending events from both splunk and non-splunk path.&lt;/P&gt;&lt;P&gt;Looking for a regex to be added as blacklist to ignore 4688 coming from *.exe files part of splunk universal forwarder path/directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?i)(?:[C-F]:\Program Files\Splunk(?:UniversalForwarder)?\bin\(?:btool|splunkd|splunk|splunk-(?:MonitorNoHandle|admon|netmon|perfmon|powershell|regmon|winevtlog|winhostinfo|winprintmon|wmi)).exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?:[a-zA-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.+\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?:[a-zA-Z]:\\\\Program Files\\\\Splunk(?:\\\\UniversalForwarder)?\\\\bin\\\\.+\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: C:\\\\Program Files\\\\SplunkUniversalForwarder\\\\bin\\\\"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: C:\\Program Files\\SplunkUniversalForwarder\\bin\\"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name: (?i)[A-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.*\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name:\s*[A-Z]:\\Program Files\\Splunk(?:\\UniversalForwarder)?\\bin\\.+\\.exe)"&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4688" Message="New Process Name:\s*[A-Z]:\\\\Program Files\\\\SplunkUniversalForwarder\\\\bin\\\\.*\\.exe"&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 08:43:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/740999#M21796</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2025-03-06T08:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741004#M21799</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206567"&gt;@sureshkumaar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you post a sample event which is being ingested (which shouldnt) so we can help work to provide the best blacklist values for this?&lt;/P&gt;&lt;P&gt;In the meantime, you might find some useful responses in the following:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Process-Name-inputs-conf-Blacklisting-Regex-Help/m-p/502522" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Process-Name-inputs-conf-Blacklisting-Regex-Help/m-p/502522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-edit-inputs-conf-to-blacklist-an-eventcode/td-p/316734?_gl=1*vt66n4*_gcl_au*NjAzOTAxOTc1LjE3MzY5MzU2MTE.*FPAU*NjAzOTAxOTc1LjE3MzY5MzU2MTE.*_ga*MTE2ODIxOTU0My4xNjIyNzA5MTMz*_ga_5EPM2P39FV*MTc0MTI1MjYwMi4yOTEuMS4xNzQxMjUzNDQwLjAuMC4zMTYwNzI5MDI.*_fplc*RUlmMXZYMldIQzFKUEdsamdtbjElMkJVSDNiZ21tZ0pBMGJKUSUyRnA5VSUyRnRnSkpxczVBSWV5dmRWMmF0WiUyQk9nY3REUTZhOHclMkZwUTUyTlBZdmRlc0gyJTJGcG9NNnFDM0NDRWdtNjlheDUlMkZSeWsyNlNLYzAlM0Q" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-edit-inputs-conf-to-blacklist-an-eventcode/td-p/316734&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 09:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741004#M21799</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-06T09:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741021#M21800</link>
      <description>&lt;P&gt;Aren't you by any chance ingesting your events as XML?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 10:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741021#M21800</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-06T10:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741089#M21803</link>
      <description>&lt;P&gt;Below is the events for 4688 where the code gets captured in a field called "EventCode"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;A new process has been created.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Creator Subject:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Security ID: NT AUTHORITY\SYSTEM&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Name: SERVERNAME$&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Domain: TRUE&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Logon ID: 0x3E7&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Target Subject:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Security ID:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Name:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Domain:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Logon ID:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Process Information:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;New Process ID: 0x2650&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;New Process Name: C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Token Elevation Type: TokenElevationTypeDefault (1)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Creator Process ID: 0xf7c&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Process Command Line:&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Mar 2025 08:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741089#M21803</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2025-03-07T08:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741090#M21804</link>
      <description>&lt;P&gt;below is inputs.conf before blacklist lines&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;renderXml = false&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 08:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741090#M21804</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2025-03-07T08:41:29Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741110#M21805</link>
      <description>&lt;P&gt;OK. You seem to be struggling a bit with the regex. I haven't read your attempts&amp;nbsp; thoroughly before but now I see that they seem to have some mistakes in one point or another.&lt;/P&gt;&lt;P&gt;Use regex101.com to verify your regexes. They don't need any escaping in config as long as you chose proper delimiters which do not interfere with the regex contents (so if you want to enclose your regex with quotes, your regex itself mustn't contain quotes and so on).&lt;/P&gt;&lt;P&gt;And I wouldn't worry about whether the group is capturing or not. It's not that important memory-wise in this case and you're not using the groups for anything anyway.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 12:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741110#M21805</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-03-07T12:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: 4688 event code to be excluded from universal forwarder directory path alone</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741660#M21848</link>
      <description>&lt;P&gt;Issue is fixed, below excluded the events when splunk*.exe is found for 4688 event code.&lt;/P&gt;&lt;P&gt;blacklist3 = EventCode="4688" Message=".*(splunk-.*\.exe|splunk\.exe|splunkd\.exe).*"&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 07:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/4688-event-code-to-be-excluded-from-universal-forwarder/m-p/741660#M21848</guid>
      <dc:creator>sureshkumaar</dc:creator>
      <dc:date>2025-03-13T07:47:43Z</dc:date>
    </item>
  </channel>
</rss>

