<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need a regex for these events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658847#M111428</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Hello, When I apply this blacklist&amp;nbsp; regex, still I can see the logs. Can we use btool to trouble shoot this issue ??&lt;BR /&gt;blacklist8 = "$XmlRegex=#Data Name='ParentProcessName'&amp;gt;C:\\Program Files\\(AzureConnectedMachineAgent\\GCArcService\\GC\\(gc_service|gc_worker)\.exe|Windows Defender Advanced Threat Protection\\(MsSense|SenseCM|SenseIR)\.exe|Rapid7\\Insight Agent\\components\\insight_agent\\3\.2\.5\.31\\ir_agent\.exe)#"&lt;BR /&gt;renderXml=true&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2023 09:59:28 GMT</pubDate>
    <dc:creator>Raj</dc:creator>
    <dc:date>2023-09-27T09:59:28Z</dc:date>
    <item>
      <title>How to create a regex for these events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658786#M111423</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Can any one pls share a regex for the below events to exclude(text in red).&lt;/P&gt;
&lt;P&gt;1.&lt;BR /&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{5484D}'/&amp;gt;&amp;lt;EventID&amp;gt;4688&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;2&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13312&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8020000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-09-26T18:27:56.545195800Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;2371&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4' ThreadID='18656'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;securejump&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;NT AUTHORITY\SYSTEM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;SECUREJUMP&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;0x37&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessId'&amp;gt;0x140&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files\Windows Defender Advanced Threat Protection\SenseCncProxy.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TokenElevationType'&amp;gt;%j1936&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;0x3520&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CommandLine'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserSid'&amp;gt;NULL SID&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetLogonId'&amp;gt;0x0&amp;lt;/Data&amp;gt;&amp;lt;Data &lt;FONT color="#FF0000"&gt;Name='ParentProcessName'&amp;gt;C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe&lt;/FONT&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='MandatoryLabel'&amp;gt;Mandatory Label\System Mandatory Level&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;
&lt;P&gt;2.&lt;BR /&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{hh}'/&amp;gt;&amp;lt;EventID&amp;gt;4688&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;2&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13312&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-09-26T18:00:46.762007500Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;146821602&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4' ThreadID='24996'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;securejump&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;NT AUTHORITY\SYSTEM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;SECUREJUMP&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;03e7&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessId'&amp;gt;0511c&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TokenElevationType'&amp;gt;%%1936&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;0x2010&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CommandLine'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserSid'&amp;gt;NULL SID&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetLogonId'&amp;gt;0x0&amp;lt;/Data&amp;gt;&amp;lt;&lt;FONT color="#FF0000"&gt;Data Name='ParentProcessName'&amp;gt;C:\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exe&lt;/FONT&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='MandatoryLabel'&amp;gt;Mandatory Label\System Mandatory Level&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;
&lt;P&gt;Need a single regex to exclude 1&amp;amp; 2 events.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625'/&amp;gt;&amp;lt;EventID&amp;gt;4688&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;2&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13312&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8020000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-09-26T17:44:16.666598900Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;146821089&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4' ThreadID='2136'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;secu&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;NT AUTHORITY\SYSTEM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;SEC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;0x3e7&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessId'&amp;gt;0x51&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Windows\System32\conhost.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TokenElevationType'&amp;gt;%%1936&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;0x3ec&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CommandLine'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserSid'&amp;gt;NULL SID&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetLogonId'&amp;gt;0x0&amp;lt;/Data&amp;gt;&amp;lt;&lt;FONT color="#FF0000"&gt;Data Name='ParentProcessName'&amp;gt;C:\Program Files\AzureConnectedMachineAgent\GCArcService\GC\gc_worker.exe&lt;/FONT&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='MandatoryLabel'&amp;gt;Mandatory Label\System Mandatory Level&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{449'/&amp;gt;&amp;lt;EventID&amp;gt;4688&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;2&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13312&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;0x8020000000000000&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-09-26T18:24:19.611633300Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;146822267&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4' ThreadID='19952'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;securejump&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;NT AUTHORITY\SYSTEM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;SECUREJUMP&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;0x3e7&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessId'&amp;gt;0x4a18&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files\Rapid7\Insight Agent\components\insight_agent\3.2.5.31\get_proxy.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TokenElevationType'&amp;gt;%%1936&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;0xdd0&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CommandLine'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserSid'&amp;gt;NULL SID&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetLogonId'&amp;gt;0x0&amp;lt;/Data&amp;gt;&amp;lt;&lt;FONT color="#FF0000"&gt;Data Name='ParentProcessName'&amp;gt;C:\Program Files\Rapid7\Insight Agent\components\insight_agent\3.2.5.31\ir_agent.exe&lt;/FONT&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='MandatoryLabel'&amp;gt;Mandatory Label\System Mandatory Level&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;
&lt;P&gt;Thanks...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:08:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658786#M111423</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-27T19:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658788#M111424</link>
      <description>&lt;P&gt;What do you mean by "exclude" here? You want to blacklist them on input or exclude them from search results? And why would you need a single regex to match dwo different patterns?&lt;/P&gt;&lt;P&gt;You put this post in "deployment architecture" section when it has nothing to do with architecture and tagged it with "deployment server" which again it has nothing to do with. So what is it about?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 19:00:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658788#M111424</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-26T19:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658796#M111425</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;hi&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Want to blacklist them on inputs as I left with only three&amp;nbsp; blacklist space.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 19:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658796#M111425</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-26T19:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658817#M111426</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@Raj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;do you want to remove all the events from the input or only the selectes part of the events?&lt;/P&gt;&lt;P&gt;If you want to remove all the events, you could use a simple regex to blacklist them:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Data Name\=\'ParentProcessName\'\&amp;gt;C:\\Program Files\\(Windows Defender Advanced Threat Protection\\MsSense\.exe)|(Windows Defender Advanced Threat Protection\\SenseIR\.exe)|(AzureConnectedMachineAgent\\GCArcService\\GC\\gc_worker\.exe)|(Rapid7\\Insight Agent\\components\\insight_agent\\3\.2\.5\.31\\ir_agent\.exe)&lt;/LI-CODE&gt;&lt;P&gt;you can check this regex at &lt;A href="https://regex101.com/r/9lsjyz/1" target="_blank"&gt;https://regex101.com/r/9lsjyz/1&lt;/A&gt;. Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 06:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658817#M111426</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-27T06:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658820#M111427</link>
      <description>&lt;P&gt;OK. That makes sense. The number of remaining blacklist entries is a valid point.&lt;/P&gt;&lt;P&gt;You can construct a regex matchig several partially alternative branches using the A|B construct.&lt;/P&gt;&lt;P&gt;Also remember that while using renderXml=true you need to blacklist by $XmlRegex field.&lt;/P&gt;&lt;P&gt;So you'd end up with something like this:&lt;/P&gt;&lt;PRE&gt;&lt;FONT color="#FF0000"&gt;blacklist9 = $XmlRegex=#Data Name='ParentProcessName'&amp;gt;C:\\Program Files\\(AzureConnectedMachineAgent\\GCArcService\\GC\\gc_worker\.exe|Rapid7\\Insight Agent\\components\\insight_agent\\3\.2\.5\.31\\ir_agent\.exe)#&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;You might need to escape the &amp;gt; sign (I never remember which solutions treated the raw '&amp;gt;' as literal '&amp;gt;' and escaped '\&amp;gt;' as end of the word. And which ones did the opposite. (I think vim was notorious for strangely (un)escaped characters inregexes).&lt;/P&gt;&lt;P&gt;As usual - try your regex at regex101.com&lt;/P&gt;&lt;P&gt;Of course if you wanted, you can combine all your 4 cases into one using the alternative grouping.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 07:23:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658820#M111427</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-27T07:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658847#M111428</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Hello, When I apply this blacklist&amp;nbsp; regex, still I can see the logs. Can we use btool to trouble shoot this issue ??&lt;BR /&gt;blacklist8 = "$XmlRegex=#Data Name='ParentProcessName'&amp;gt;C:\\Program Files\\(AzureConnectedMachineAgent\\GCArcService\\GC\\(gc_service|gc_worker)\.exe|Windows Defender Advanced Threat Protection\\(MsSense|SenseCM|SenseIR)\.exe|Rapid7\\Insight Agent\\components\\insight_agent\\3\.2\.5\.31\\ir_agent\.exe)#"&lt;BR /&gt;renderXml=true&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 09:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658847#M111428</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-27T09:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658848#M111429</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;only the selected part of the events i am trying to exclude..&lt;BR /&gt;How we can trouble shoot splunk locally using btool ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 11:17:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658848#M111429</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-27T11:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658861#M111430</link>
      <description>&lt;P&gt;Regexes in blacklists can be tricky sometimes. btool will just show you what is the effective config you just wrote so it won't show you if it works or not.&lt;/P&gt;&lt;P&gt;I assume you restarted your forwarder after configuring the blacklist.&lt;/P&gt;&lt;P&gt;Anyway, you should &lt;STRONG&gt;not&lt;/STRONG&gt; enclose the blacklist parameter in quotes.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 11:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658861#M111430</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-27T11:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658863#M111431</link>
      <description>&lt;P&gt;Yes I had restarted forwarder but in the host&amp;nbsp; inputs.conf I dnt see the applied regex from deployment server !&lt;/P&gt;&lt;P&gt;As we are using all the blacklisted in the quotes!!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 11:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658863#M111431</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-27T11:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658864#M111432</link>
      <description>&lt;P&gt;Wait. What do you mean? You're editing the app on DS? Then you have to reload the deployment server (you don't have to restart it) so that it notices a new version of the app and offers it to the forwarder(s) for download.&lt;/P&gt;&lt;P&gt;Also:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Inputsconf#Event_Log_allow_list_and_deny_list_formats" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Inputsconf#Event_Log_allow_list_and_deny_list_formats&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 11:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658864#M111432</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-27T11:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658868#M111433</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I tried to refresh/debug inputs.conf using btool in deployment server , I can see the below errors.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Refreshing admin/collections-conf&lt;BR /&gt;RESTException [HTTP 503] [{'type': 'ERROR', 'code': None, 'text': 'KV Store initialization failed.&lt;BR /&gt;Please contact your system administrator.'}]&lt;BR /&gt;&lt;BR /&gt;Refreshing admin/deploymentserver SplunkdConnectionException Splunkd daemon is not responding: ('Error connecting to /servicesNS/nobody/search/admin/deploymentserver/_reload: The read operation timed out',)&lt;BR /&gt;&lt;BR /&gt;Refreshing admin/ingest-rfs-destinations SplunkdConnectionException Splunkd daemon is not responding: ('Error connecting to /servicesNS/nobody/search/admin/ingest-rfs-destinations/_reload: The read operation timed out',)&lt;BR /&gt;&lt;BR /&gt;Refreshing admin/serverclasses SplunkdConnectionException Splunkd daemon is not responding: ('Error connecting to /servicesNS/nobody/search/admin/serverclasses/_reload: The read operation timed out',)&lt;/P&gt;&lt;P&gt;How we can trouble shoot this ERROR Messages ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 12:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658868#M111433</guid>
      <dc:creator>Raj</dc:creator>
      <dc:date>2023-09-28T12:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Need a regex for these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658885#M111436</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@Raj&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to remove only a part of events, you have to follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Data/Anonymizedata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Data/Anonymizedata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you should insert in your props.conf&amp;nbsp; one&amp;nbsp;&lt;SPAN&gt;SEDCMD-&amp;lt;class&amp;gt; = y/&amp;lt;string1&amp;gt;/&amp;lt;string2&amp;gt;/g, using my above regex:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-remove_strings = s/Data Name\=\'ParentProcessName\'\&amp;gt;C:\\Program Files\\(Windows Defender Advanced Threat Protection\\MsSense\.exe)|(Windows Defender Advanced Threat Protection\\SenseIR\.exe)|(AzureConnectedMachineAgent\\GCArcService\\GC\\gc_worker\.exe)|(Rapid7\\Insight Agent\\components\\insight_agent\\3\.2\.5\.31\\ir_agent\.exe)//g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 16:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-regex-for-these-events/m-p/658885#M111436</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-27T16:10:04Z</dc:date>
    </item>
  </channel>
</rss>

