<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WMI input and whitelisting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WMI-input-and-whitelisting/m-p/568242#M100856</link>
    <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;I finally managed to set up WMI-based event log monitoring and it seems to work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The problem is that it's gonna give me way to many events. I want to pull just a subset of the events from the Applicatonlog. With ordinary WinEventLog input I could set up a whitelist/blacklist to limit the processed events at the forwarder level. The same doesn't seem to work with the WMI:whatever type of input.&lt;/P&gt;&lt;P&gt;Is there indeed no way to limit the ingested events? Do I have to do it further down the stream by selective routing on HF?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 13:26:34 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-09-23T13:26:34Z</dc:date>
    <item>
      <title>WMI input and whitelisting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WMI-input-and-whitelisting/m-p/568242#M100856</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;I finally managed to set up WMI-based event log monitoring and it seems to work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The problem is that it's gonna give me way to many events. I want to pull just a subset of the events from the Applicatonlog. With ordinary WinEventLog input I could set up a whitelist/blacklist to limit the processed events at the forwarder level. The same doesn't seem to work with the WMI:whatever type of input.&lt;/P&gt;&lt;P&gt;Is there indeed no way to limit the ingested events? Do I have to do it further down the stream by selective routing on HF?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 13:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WMI-input-and-whitelisting/m-p/568242#M100856</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-23T13:26:34Z</dc:date>
    </item>
  </channel>
</rss>

