<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WMI winevent log Events not being sent to nullQueue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WMI-winevent-log-Events-not-being-sent-to-nullQueue/m-p/575483#M101723</link>
    <description>&lt;P&gt;I am trying to send the following WMI winevent log event to the Null queue as it needs to be dropped.But this dosn't seems to be working. Can someone help me on this?&lt;/P&gt;&lt;P&gt;I have configured the props &amp;amp; transform in Heavy Forwarder like-&lt;/P&gt;&lt;P&gt;props.conf&lt;BR /&gt;[source::WinEventLog:Microsoft-Windows-WMI-Activity/Operational]&lt;BR /&gt;TRANSFORMS-null = wmi-setnull&lt;/P&gt;&lt;P&gt;transforms.conf&lt;BR /&gt;[wmi-setnull]&lt;BR /&gt;REGEX =((.|\n)*)EventCode=5857\s+((.|\n)*)ProviderPath\s+=\s+(%systemroot%\\system32\\wbem\\(wmiprov\.dll|ntevt\.dll|wmiprvsd\.dll)|C:\\Windows\\(System32\\wbem\\krnlprov\.dll|CCM\\ccmsdkprovider\.dll)|C:\\Program\sFiles\\(Microsoft\sSQL\sServer\\.*\\Shared\\sqlmgmprovider\.dll|VMware\\VMware Tools\\vmStatsProvider\\win64\\vmStatsProvider\.dll))&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 16:13:25 GMT</pubDate>
    <dc:creator>anupgurung</dc:creator>
    <dc:date>2021-11-18T16:13:25Z</dc:date>
    <item>
      <title>WMI winevent log Events not being sent to nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WMI-winevent-log-Events-not-being-sent-to-nullQueue/m-p/575483#M101723</link>
      <description>&lt;P&gt;I am trying to send the following WMI winevent log event to the Null queue as it needs to be dropped.But this dosn't seems to be working. Can someone help me on this?&lt;/P&gt;&lt;P&gt;I have configured the props &amp;amp; transform in Heavy Forwarder like-&lt;/P&gt;&lt;P&gt;props.conf&lt;BR /&gt;[source::WinEventLog:Microsoft-Windows-WMI-Activity/Operational]&lt;BR /&gt;TRANSFORMS-null = wmi-setnull&lt;/P&gt;&lt;P&gt;transforms.conf&lt;BR /&gt;[wmi-setnull]&lt;BR /&gt;REGEX =((.|\n)*)EventCode=5857\s+((.|\n)*)ProviderPath\s+=\s+(%systemroot%\\system32\\wbem\\(wmiprov\.dll|ntevt\.dll|wmiprvsd\.dll)|C:\\Windows\\(System32\\wbem\\krnlprov\.dll|CCM\\ccmsdkprovider\.dll)|C:\\Program\sFiles\\(Microsoft\sSQL\sServer\\.*\\Shared\\sqlmgmprovider\.dll|VMware\\VMware Tools\\vmStatsProvider\\win64\\vmStatsProvider\.dll))&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:13:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WMI-winevent-log-Events-not-being-sent-to-nullQueue/m-p/575483#M101723</guid>
      <dc:creator>anupgurung</dc:creator>
      <dc:date>2021-11-18T16:13:25Z</dc:date>
    </item>
  </channel>
</rss>

