<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent the default logs from being forwarded (Windows UF) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/565296#M100600</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/65882"&gt;@xnx_1012&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first if you have "disabled=1" the stanza isn't read from Splunk so the blacklist configuration isn't used.&lt;/P&gt;&lt;P&gt;In addition, you're speaking of Splunk logs, that are in another inputs.conf, in "SPLUNK_HOME\etc\system\default\inputs.conf".&lt;/P&gt;&lt;P&gt;So if you want to block these logs, copy the inputs.conf from system\default to system\local and put "disabled=1" in all stanzas of inputs.conf.&lt;/P&gt;&lt;P&gt;Only to understand: why do you want to block these logs?&lt;/P&gt;&lt;P&gt;the internal Splunk logs don't compute any license consuption and are used to monitor the Splunk infrastructure, so I'd avoid to block them because they are useful!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2021 09:00:53 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-08-31T09:00:53Z</dc:date>
    <item>
      <title>How to prevent the default logs from being forwarded (Windows UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/565295#M100599</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Whenever I forward something, these logs always get forwarded despite I blacklisted it in the inputs .conf. Is there any way for it to be not forwarded at all&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="xnx_1012_0-1630399852443.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15790i9F52F7E68191E799/image-size/medium?v=v2&amp;amp;px=400" role="button" title="xnx_1012_0-1630399852443.png" alt="xnx_1012_0-1630399852443.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inputs.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;index = windows_test&lt;BR /&gt;whitelist = EventCode=%^(4634)$%&lt;BR /&gt;sourcetype = ad:security&lt;BR /&gt;disabled = 0&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME\var\log\splunk]&lt;BR /&gt;disabled = 1&lt;BR /&gt;blacklist = %SplunkUniversalForwarder%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 08:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/565295#M100599</guid>
      <dc:creator>xnx_1012</dc:creator>
      <dc:date>2021-08-31T08:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent the default logs from being forwarded (Windows UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/565296#M100600</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/65882"&gt;@xnx_1012&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first if you have "disabled=1" the stanza isn't read from Splunk so the blacklist configuration isn't used.&lt;/P&gt;&lt;P&gt;In addition, you're speaking of Splunk logs, that are in another inputs.conf, in "SPLUNK_HOME\etc\system\default\inputs.conf".&lt;/P&gt;&lt;P&gt;So if you want to block these logs, copy the inputs.conf from system\default to system\local and put "disabled=1" in all stanzas of inputs.conf.&lt;/P&gt;&lt;P&gt;Only to understand: why do you want to block these logs?&lt;/P&gt;&lt;P&gt;the internal Splunk logs don't compute any license consuption and are used to monitor the Splunk infrastructure, so I'd avoid to block them because they are useful!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 09:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/565296#M100600</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-31T09:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent the default logs from being forwarded (Windows UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680612#M113706</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this post as I am trying to solve the same issue. I followed your suggestion and copied all the monitor&amp;nbsp; stanzas from system\default\inputs.conf to my inputs file in system\local\inputs.conf; and inserted "disable = 1" to all of them. Then I restarted splunk.&lt;/P&gt;
&lt;P&gt;However, network capture from my Splunk Server still showing all the log entries being forwarded.&lt;/P&gt;
&lt;P&gt;Below is my inputs.conf file. Do you know what could be the issue?&lt;/P&gt;
&lt;P&gt;Thanks, Billy.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://C:\Program Files\SplunkUniversalForwarder\var\log\splunk]
disabled = 1
index = _internal

[monitor://C:\Program Files\SplunkUniversalForwarder\var\log\watchdog\watchdog.log*]
disabled = 1
index = _internal

[monitor://C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage_summary.log]
disabled = 1
index = _telemetry

[monitor://C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunk_instrumentation_cloud.log*]
disabled = 1
index = _telemetry
sourcetype = splunk_cloud_telemetry

[monitor://C:\Program Files\SplunkUniversalForwarder\etc\splunk.version]
disabled = 1
_TCP_ROUTING = *
index = _internal
sourcetype=splunk_version

[monitor://C:\Program Files\SplunkUniversalForwarder\var\log\splunk\configuration_change.log]
disabled = 1
index = _configtracker

[WinEventLog://Security]
disabled = 0
renderXml = 1
whitelist = 4624, 4634&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 13 Mar 2024 22:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680612#M113706</guid>
      <dc:creator>billy</dc:creator>
      <dc:date>2024-03-13T22:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent the default logs from being forwarded (Windows UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680646#M113711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265849"&gt;@billy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first, don't attach a new question to another one especially when closed because it's more difficoult to have an answer, it's always better to open a new question, even if with the same topic, to have a surely faster and probably better answer.&lt;/P&gt;&lt;P&gt;Anyway, in this way you block the Splunk monitoring and it isn't a good idea because you're blind on Splunk running.&lt;/P&gt;&lt;P&gt;Why do you want this?&lt;/P&gt;&lt;P&gt;the Splunk logs don't consume license and you can limit the storage consuption using a limited (e.g. 7 days) retention on these logs.&lt;/P&gt;&lt;P&gt;Anyway, are you sure that you continue to receive these logs from that Forwarder?&lt;/P&gt;&lt;P&gt;I say this becsue with the configuration you shared isn't possible to receive these logs from that Forwarder.&lt;/P&gt;&lt;P&gt;Check if the logs you're receiving have that source (the ones in the monitor stanza header) and that host (the Forwarder where you changed the configuration.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 07:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680646#M113711</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-14T07:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent the default logs from being forwarded (Windows UF)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680781#M113735</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe, thanks for the guidance! As you can tell I am a newbie here &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Actually I did posted a new question here&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-to-forward-only-Windows-events-XML-to-a-3rd-party-system/td-p/680458" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-to-forward-only-Windows-events-XML-to-a-3rd-party-system/td-p/680458&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I was struggling and saw your Q/A.&lt;/P&gt;&lt;P&gt;I understand filtering at forwarder is not a good idea.&lt;/P&gt;&lt;P&gt;In any case I've figured out how exactly to filter things out in Splunk Server so my 3rd party partner would get XmlWinEvtLog messages only.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;Billy&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 02:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-prevent-the-default-logs-from-being-forwarded-Windows-UF/m-p/680781#M113735</guid>
      <dc:creator>billy</dc:creator>
      <dc:date>2024-03-15T02:13:49Z</dc:date>
    </item>
  </channel>
</rss>

