<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to blacklist security events by regex? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/658091#M111337</link>
    <description>&lt;P&gt;Hi,&amp;nbsp; My ask is like can we adjust these regex under one or more blacklist so that we can add few more regex for limitation issue like 10 is max.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 07:46:51 GMT</pubDate>
    <dc:creator>smith_</dc:creator>
    <dc:date>2023-09-20T07:46:51Z</dc:date>
    <item>
      <title>How to blacklist security events by regex?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/657705#M111311</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm attempting to exclude specific undesired data from the security logs. Is there a way to minimize the number of items on the exclusion list, considering that we can only add up to 10 items to the blacklist due to limitations.&amp;nbsp;&lt;SPAN&gt;Is there a possibility of consolidating the blacklist by, for example, appending a "|" (pipe) at the end of each blacklisted item, thereby reducing the total number of entries in the blacklist while still achieving the desired exclusion?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;blacklist1 = EventCode="4662" Message="Object Type:(?!\s*(groupPolicyContainer|computer|user))"&lt;BR /&gt;blacklist2 = EventCode="4648|5145|4799|5447|4634|5156|4663|4656|5152|5157|4658|4673|4661|4690|4932|4933|5158|4957|5136|4674|4660|4670|5058|5061|4985|4965"&lt;BR /&gt;blacklist3 = EventCode="4688" Message="(?:New Process Name:).+(?:SplunkUniversalForwarder\\bin\\splunk.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunkd.exe)|.+(?:SplunkUniversalForwarder\\bin\\btool.exe)"&lt;BR /&gt;blacklist4 = EventCode="4688" Message="(?:New Process Name:).+(?:SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-powershell.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-regmon.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-netmon.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-admon.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-perfmon.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk-wmi.exe)|.+(?:SplunkUniversalForwarder\\bin\\splunk\-winhostinfo\.exe)"&lt;BR /&gt;blacklist5 = EventCode="4688" Message="(?:Process Command Line:).+(?:system32\\SearchFilterHost.exe)|.+(?:find/i)|.+(?:WINDOWS\\system32\\conhost.exe)"&lt;BR /&gt;renderXml=true&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 16:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/657705#M111311</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-09-26T16:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist security events by regex?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/657808#M111315</link>
      <description>&lt;P&gt;Yes, what you describe is allowed as long as the text after the '=' is a valid regular expression.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Sep 2023 16:18:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/657808#M111315</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-16T16:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist security events by regex?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/658091#M111337</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; My ask is like can we adjust these regex under one or more blacklist so that we can add few more regex for limitation issue like 10 is max.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 07:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/658091#M111337</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-09-20T07:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist security events by regex?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/658148#M111338</link>
      <description>&lt;P&gt;I believe I already said you can do that.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 15:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-security-events-by-regex/m-p/658148#M111338</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-09-20T15:01:27Z</dc:date>
    </item>
  </channel>
</rss>

