<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: regex in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667214#M111908</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230424"&gt;@TheBravoSierra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share a sample of your logs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 16:28:17 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-11-02T16:28:17Z</dc:date>
    <item>
      <title>regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667213#M111907</link>
      <description>&lt;P&gt;Can someone help me with these regex on inputs.conf on universal forwarder?&lt;BR /&gt;&lt;BR /&gt;For some reason, isn't working. Much appreciated!&lt;BR /&gt;&lt;BR /&gt;blacklist7 = EventCode=4673 Process_Name="C:\Program Files\WindowsApps\AD2F1837.myHP_25.52341.876.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe"&lt;BR /&gt;&lt;BR /&gt;blacklist8 = EventCode=4673 Process_Name="C:\Program Files\WindowsApps\AD2F1837.myHP_26.52343.948.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe"&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:24:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667213#M111907</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2023-11-02T16:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667214#M111908</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230424"&gt;@TheBravoSierra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share a sample of your logs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667214#M111908</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-02T16:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667215#M111909</link>
      <description>&lt;P&gt;11/02/2023 10:28:49 AM LogName=Security EventCode=4673 EventType=0 ComputerName=XXXX SourceName=Microsoft Windows security auditing. Type=Information RecordNumber=XXXX Keywords=Audit Failure TaskCategory=Sensitive Privilege Use OpCode=Info Message=A privileged service was called. Subject: Security ID:XXXX Account Name:XXXX Account Domain:XXXX Logon ID:XXXX Service: Server: Security Service Name: - Process: Process ID:XXXX Process Name: C:\Program Files\WindowsApps\AD2F1837.myHP_25.52341.876.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe Service Request Information: Privileges: SeTcbPrivilege&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667215#M111909</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2023-11-02T16:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667216#M111910</link>
      <description>&lt;P&gt;I was able to successfully blacklist the below, so I am not sure why the difference.&lt;BR /&gt;&lt;BR /&gt;blacklist6 = EventCode=5156 Application_Name="\device\harddiskvolume3\gcti\tsrvciscocm\cisco_cucm_tserver_bu_2\ciscocm_server.exe"&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;Application Name: \device\harddiskvolume3\gcti\tsrvciscocm\cisco_cucm_tserver_bu_2\ciscocm_server.exe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667216#M111910</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2023-11-02T16:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: regex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667220#M111911</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230424"&gt;@TheBravoSierra&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist7 = EventCode\=4673.*Process Name:\s*C:\\Program Files\\WindowsApps.*\\win32\\DesktopExtension\.exe&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 16:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/regex/m-p/667220#M111911</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-02T16:47:17Z</dc:date>
    </item>
  </channel>
</rss>

