<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Event filtering on Heavy-Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/565682#M100628</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was finally able to filter with this stanza&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1630592863922.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15818i5A5084B0985B9FF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1630592863922.png" alt="splunkcol_0-1630592863922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;note: omit the bracket that is missing at the beginning&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2021 14:30:33 GMT</pubDate>
    <dc:creator>splunkcol</dc:creator>
    <dc:date>2021-09-02T14:30:33Z</dc:date>
    <item>
      <title>Windows Event filtering on Heavy-Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/550305#M91391</link>
      <description>&lt;P&gt;I am ingesting 100 windows machines and the events that are affecting my license consumption the most are 5156,5157,5158, 4658,4663, 4656, 4690.&lt;/P&gt;&lt;P&gt;I don't really know if I should filter them or if I can get out some correlation event that is valuable.&lt;/P&gt;&lt;P&gt;I have already filtered the first 2 according to Splunk documentation.&lt;/P&gt;&lt;P&gt;But my client doesn't want me to filter the EventCode if not the "Application Name"&lt;/P&gt;&lt;P&gt;What I see differently is that "EventCode" is pasted and "Aplication Name" has a blank space and I don't know how I should put the regular expression if I want to filter only by "Aplication name"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example&lt;BR /&gt;Application Name: \device\harddiskvolume2\windows\system32\svchost.exe&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;BR /&gt;[WinEventLog:Security]
TRANSFORMS-wmi=wminull&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;BR /&gt;[wminull]
REGEX=(?m)^EventCode=(592|593)
DEST_KEY=queue
FORMAT=nullQueue&lt;/PRE&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.2/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1620085893580.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14024i4DE744460F498999/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1620085893580.png" alt="splunkcol_0-1620085893580.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 00:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/550305#M91391</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2021-05-04T00:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event filtering on Heavy-Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/550743#M91441</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to achieve filtering like this&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;BR /&gt;[wminull]
REGEX=(&lt;SPAN&gt;svchost.exe&lt;/SPAN&gt;)
DEST_KEY=queue
FORMAT=nullQueue&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 01:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/550743#M91441</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2021-05-07T01:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event filtering on Heavy-Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/565682#M100628</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was finally able to filter with this stanza&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkcol_0-1630592863922.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15818i5A5084B0985B9FF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="splunkcol_0-1630592863922.png" alt="splunkcol_0-1630592863922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;note: omit the bracket that is missing at the beginning&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 14:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-filtering-on-Heavy-Forwarder/m-p/565682#M100628</guid>
      <dc:creator>splunkcol</dc:creator>
      <dc:date>2021-09-02T14:30:33Z</dc:date>
    </item>
  </channel>
</rss>

