<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need an xml regex to exclude these events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669882#M112322</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yes they're windows events...&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 16:54:49 GMT</pubDate>
    <dc:creator>smith_</dc:creator>
    <dc:date>2023-11-27T16:54:49Z</dc:date>
    <item>
      <title>Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669854#M112313</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is there someone here who can create an XML regular expression for these events to prevent them from being ingested into Splunk?&lt;BR /&gt;&lt;BR /&gt;1. Sample Event:&lt;BR /&gt;&lt;BR /&gt;&amp;lt;Event xmlns='&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;'&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Security-Auditing' Guid='{XXXXX}'/&amp;gt;&amp;lt;EventID&amp;gt;4688&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;2&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;0&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;13312&amp;lt;/Task&amp;gt;&amp;lt;xxx&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;xxxxx&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2023-11-27'/&amp;gt;&amp;lt;EventRecordID&amp;gt;151284011&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4' ThreadID='8768'/&amp;gt;&amp;lt;Channel&amp;gt;Security&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;XXX.com&amp;lt;/Computer&amp;gt;&amp;lt;Security/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='SubjectUserSid'&amp;gt;xxx\SYSTEM&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectUserName'&amp;gt;XXX$&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectDomainName'&amp;gt;EC&amp;lt;/Data&amp;gt;&amp;lt;Data Name='SubjectLogonId'&amp;gt;xxx&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessId'&amp;gt;0x3878&amp;lt;/Data&amp;gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\Patch\tools\TaniumExecWrapper.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TokenElevationType'&amp;gt;%%xxxx&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;xxxx&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CommandLine'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserSid'&amp;gt;NULL SID&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetUserName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetDomainName'&amp;gt;-&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetLogonId'&amp;gt;xxx&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ParentProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\TaniumClient.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='MandatoryLabel'&amp;gt;Mandatory Label\System Mandatory Level&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;THANKS&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 13:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669854#M112313</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-12-06T13:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669858#M112315</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: do you want to filter your logs to send these event to nullqueue or do you want to delete part of these events?&lt;/P&gt;&lt;P&gt;in the first case, you have to follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Routeandfilterdatad" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Routeandfilterdatad&lt;/A&gt;&amp;nbsp;using this regex&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\&amp;lt;Event xmlns\=\'http:\/\/schemas\.microsoft\.com\/win\/\d+\/\d+\/events\/event\'&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;if you can share also events to maintain, I could be more sure abut the regex.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669858#M112315</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-27T14:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669876#M112320</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I want to exclude these events by blacklisting&amp;nbsp; on inputs.conf so that it can be stop ingesting into splunk .........&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:19:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669876#M112320</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-11-27T16:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669877#M112321</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are they windows events?&lt;/P&gt;&lt;P&gt;if yes, you can blacklist them, if not, you cannot blacklist them in inputs.conf.&lt;/P&gt;&lt;P&gt;Then you have to check if the regex I shared is correct or too large, for this reasono I asked to share also events to not discard.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669877#M112321</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-27T16:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669882#M112322</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yes they're windows events...&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669882#M112322</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-11-27T16:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669890#M112323</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, I'm not sure that the regex I shared is ok for you: you shared events to discard, but I also need events to not discard, could you share them?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:03:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669890#M112323</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-27T17:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669892#M112324</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;These are the events which I want to exclude&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\Patch\tools\TaniumExecWrapper.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='ParentProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\TaniumClient.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='ParentProcessName'&amp;gt;C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\Patch\tools\TaniumFileInfo.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='ParentProcessName'&amp;gt;C:\Program Files (x86)\Tanium\Tanium Client\Patch\tools\TaniumExecWrapper.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='NewProcessName'&amp;gt;C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\10.8560.25364.1036\SenseCnCProxy.exe&amp;lt;/Data&amp;gt;&lt;BR /&gt;&amp;lt;Data Name='ParentProcessName'&amp;gt;C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\10.8560.25364.1036\MsSense.exe&amp;lt;/Data&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669892#M112324</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-11-27T17:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669893#M112325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to discard the four samples you shared in the original question but not the last one, the above regex is correct, as you can check at&amp;nbsp;&lt;A href="https://regex101.com/r/x5zuYc/1" target="_blank"&gt;https://regex101.com/r/x5zuYc/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669893#M112325</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-27T17:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669896#M112326</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Is this regex going to exclude all the windows events starting with this "\&amp;lt;Event xmlns\=\'http:\/\/schemas\.microsoft\.com\/win\/\d+\/\d+\/events\/event\'&amp;gt;"&amp;nbsp; &amp;nbsp;right?&lt;BR /&gt;&lt;BR /&gt;By the way my intention is to exclude all the secutiy tool events specific to eventcode&amp;nbsp;&lt;SPAN&gt;4688&amp;nbsp;&lt;/SPAN&gt;eg, tanium,splunk ,windows defender etc.,&lt;BR /&gt;&lt;BR /&gt;can we whitelist all the windows events like C:\\ Windows\\*&amp;nbsp;&lt;BR /&gt;we need to ingesting all the windows events like eg. cmd.exe,reg.exe etc.,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks..&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669896#M112326</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-11-27T17:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Need an xml regex to exclude these events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669909#M112329</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;both the approaches are correct.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:58:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-an-xml-regex-to-exclude-these-events/m-p/669909#M112329</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-27T17:58:18Z</dc:date>
    </item>
  </channel>
</rss>

