<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering Windows 4662 logs in Windows - Not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611075#M105856</link>
    <description>&lt;P&gt;Object_Type is not one of the supported fields for blacklist.&amp;nbsp; IME, Splunk does not handle lookahead/lookbehind well, so try to avoid them.&amp;nbsp; Have you tried this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist1 = EventCode="4662" Message="Object Type:\s*(x|y)"&lt;/LI-CODE&gt;</description>
    <pubDate>Sun, 28 Aug 2022 13:17:49 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-08-28T13:17:49Z</dc:date>
    <item>
      <title>Filtering Windows 4662 logs in Windows - Not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611072#M105854</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I am trying to filter out those noisy 4662 logs eating our license like anything as recommended in Splunk blogs and forums.&lt;/P&gt;
&lt;P&gt;Tried the below stanza for 4662 to blacklist everything except GPO related events, but not working as expected. Any help to fix the regex part.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Raw Message is below :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Message=An&lt;/SPAN&gt; &lt;SPAN class=""&gt;operation&lt;/SPAN&gt; &lt;SPAN class=""&gt;was&lt;/SPAN&gt; &lt;SPAN class=""&gt;performed&lt;/SPAN&gt; &lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;object.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Subject&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Security&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:&lt;/SPAN&gt; &lt;SPAN class=""&gt;$&lt;/SPAN&gt; &lt;SPAN class=""&gt;Account&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;$&lt;/SPAN&gt; &lt;SPAN class=""&gt;Account&lt;/SPAN&gt; &lt;SPAN class=""&gt;Domain:&lt;/SPAN&gt; &amp;nbsp;&lt;SPAN class=""&gt;Logon&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x7F897031&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object&lt;/SPAN&gt; &lt;SPAN class=""&gt;Server:&lt;/SPAN&gt; &lt;SPAN class=""&gt;DS&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;groupPolicyContainer&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name:&lt;/SPAN&gt; &lt;SPAN class=""&gt;CN=&lt;/SPAN&gt;{&lt;SPAN class=""&gt;123456-D64E-4013-ACC5-F78A&lt;/SPAN&gt;}&lt;SPAN class=""&gt;CN=Policies&lt;/SPAN&gt;,&lt;SPAN class=""&gt;CN=System&lt;/SPAN&gt;,&lt;SPAN class=""&gt;DC=xyz&lt;/SPAN&gt;,&lt;SPAN class=""&gt;DC=xyyz&lt;/SPAN&gt;,&lt;SPAN class=""&gt;DC=com&lt;/SPAN&gt; &lt;SPAN class=""&gt;Handle&lt;/SPAN&gt; &lt;SPAN class=""&gt;ID:&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Operation:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Operation&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object&lt;/SPAN&gt; &lt;SPAN class=""&gt;Access&lt;/SPAN&gt; &lt;SPAN class=""&gt;Accesses:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Read&lt;/SPAN&gt; &lt;SPAN class=""&gt;Property&lt;/SPAN&gt; &lt;SPAN class=""&gt;Access&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mask:&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x10&lt;/SPAN&gt; &lt;SPAN class=""&gt;Properties:&lt;/SPAN&gt; --&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Public&lt;/SPAN&gt; &lt;SPAN class=""&gt;Information&lt;/SPAN&gt; &lt;SPAN class=""&gt;distinguishedName&lt;/SPAN&gt; &lt;SPAN class=""&gt;groupPolicyContainer&lt;/SPAN&gt; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Information:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Parameter&lt;/SPAN&gt; &lt;SPAN class=""&gt;1:&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Parameter&lt;/SPAN&gt; &lt;SPAN class=""&gt;2:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Can we filter directly based on Object_Type instead of Message field like :&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;blacklist1 = EventCode="4662" Object_Type="(x|y)".&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Any help would be great! Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 13:14:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611072#M105854</guid>
      <dc:creator>kknair007</dc:creator>
      <dc:date>2022-08-29T13:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Windows 4662 logs in Windows - Not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611075#M105856</link>
      <description>&lt;P&gt;Object_Type is not one of the supported fields for blacklist.&amp;nbsp; IME, Splunk does not handle lookahead/lookbehind well, so try to avoid them.&amp;nbsp; Have you tried this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist1 = EventCode="4662" Message="Object Type:\s*(x|y)"&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 28 Aug 2022 13:17:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611075#M105856</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-28T13:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Windows 4662 logs in Windows - Not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611135#M105863</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;I tried the below as you suggested, not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4662" Message="Object Type:\s*(dnsNode|dnsZone|container|computer|SecretObject)"&lt;/P&gt;&lt;P&gt;\s* caters to all whitespaces. What about other characters and numbers in Message field which has to be matched since Object Type is coming somewhere in the middle as per the raw event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you pls shed some light on this regex, Rich?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 10:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611135#M105863</guid>
      <dc:creator>kknair007</dc:creator>
      <dc:date>2022-08-29T10:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Windows 4662 logs in Windows - Not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611143#M105864</link>
      <description>&lt;P&gt;There is only whitespace between "Object Type:" and the value so "\s*" is correct.&amp;nbsp; The characters before "Object Type" are skipped automatically.&lt;/P&gt;&lt;P&gt;If the goal is to index only events of a certain Object Type then you probably want a whitelist rather than blacklist.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 12:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/611143#M105864</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-29T12:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering Windows 4662 logs in Windows - Not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/630001#M108008</link>
      <description>&lt;P&gt;I know this is an old thread, but we have this in our Windows_TA local.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;blacklist1 = EventCode="4662|566" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Feb 2023 00:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-Windows-4662-logs-in-Windows-Not-working/m-p/630001#M108008</guid>
      <dc:creator>mweb</dc:creator>
      <dc:date>2023-02-08T00:44:20Z</dc:date>
    </item>
  </channel>
</rss>

