<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to filter events from Eventlog? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-events-from-Eventlog/m-p/660288#M111656</link>
    <description>&lt;P&gt;We are using the Splunk Universal Forwarder on Windows servers to capture event viewer logs into Splunk.&amp;nbsp; We have a known issue with a product causing a large number of events to be recorded in the event viewer which are then sent into Splunk.&amp;nbsp; How can we filter out a specific event from the Universal Forwarder so that it is not sent into Splunk?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2026 16:35:00 GMT</pubDate>
    <dc:creator>infra4scc</dc:creator>
    <dc:date>2026-04-01T16:35:00Z</dc:date>
    <item>
      <title>How to filter events from Eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-events-from-Eventlog/m-p/660288#M111656</link>
      <description>&lt;P&gt;We are using the Splunk Universal Forwarder on Windows servers to capture event viewer logs into Splunk.&amp;nbsp; We have a known issue with a product causing a large number of events to be recorded in the event viewer which are then sent into Splunk.&amp;nbsp; How can we filter out a specific event from the Universal Forwarder so that it is not sent into Splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 16:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-events-from-Eventlog/m-p/660288#M111656</guid>
      <dc:creator>infra4scc</dc:creator>
      <dc:date>2026-04-01T16:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter events from Eventlog?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-events-from-Eventlog/m-p/660291#M111657</link>
      <description>&lt;P&gt;See this document.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf#Event_Log_filtering" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf#Event_Log_filtering&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Just be aware that there are two different formats and you use one of them depending on whether you ingest your events in "old style" plain text format or as XML.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:44:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-events-from-Eventlog/m-p/660291#M111657</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-10T19:44:18Z</dc:date>
    </item>
  </channel>
</rss>

