<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673142#M112752</link>
    <description>&lt;P&gt;I see that the desktopexetension.exe is also in the message so would something like this work?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist = EventCode=4673 message="DesktopExtension.exe"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is an example message:&lt;BR /&gt;A privileged service was called. Subject: Service: Server: Security Service Name: - Process: Process ID: 0x2fcc Process Name: C:\Program Files\WindowsApps\AD2F1837.myHP_26.52343.948.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe Service Request Information: Privileges: SeTcbPrivilege&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2024 15:56:10 GMT</pubDate>
    <dc:creator>EiffelPalace</dc:creator>
    <dc:date>2024-01-03T15:56:10Z</dc:date>
    <item>
      <title>Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673056#M112741</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am trying to blacklist this app that is generating a ton of Windows Event logs; till I find what app it is and uninstall it. This is for HP's DesktopExtension.exe. The weird thing is that it is only running on about 30 devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the current section in inputs.conf :&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;blacklist3 = EventCode=4673 ProcessName="*\\DesktopExtension.exe*"&lt;BR /&gt;renderXml=false&lt;BR /&gt;index=oswinsec&lt;BR /&gt;&lt;BR /&gt;However even after restarting the splunk forwarder the events still appear. I verified one of the hosts has the correct inputs.conf. I have also tried&lt;BR /&gt;blacklist3 = EventCode=4673 ProcessName="&lt;SPAN&gt;C:\Program Files\WindowsApps\AD2F1837.myHP_28.52349.1300.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe&lt;/SPAN&gt;""&lt;BR /&gt;&lt;BR /&gt;Here is an example of the log/event:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;LogName=Security&lt;/DIV&gt;&lt;DIV&gt;EventCode=4673&lt;/DIV&gt;&lt;DIV&gt;EventType=0&lt;/DIV&gt;&lt;DIV&gt;ComputerName=*********&lt;/DIV&gt;&lt;DIV&gt;SourceName=Microsoft Windows security auditing.&lt;/DIV&gt;&lt;DIV&gt;Type=Information&lt;/DIV&gt;&lt;DIV&gt;RecordNumber=10115718&lt;/DIV&gt;&lt;DIV&gt;Keywords=Audit Failure&lt;/DIV&gt;&lt;DIV&gt;TaskCategory=Sensitive Privilege Use&lt;/DIV&gt;&lt;DIV&gt;OpCode=Info&lt;/DIV&gt;&lt;DIV&gt;Message=A privileged service was called.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Subject:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Security ID: *****************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Name: ****************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Account Domain: ***********&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Logon ID: ****************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Service:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Server: Security&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Service Name: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Process:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Process ID: 0x6604&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Process Name: C:\Program Files\WindowsApps\AD2F1837.myHP_28.52349.1300.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Service Request Information:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any tips?&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jan 2024 20:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673056#M112741</guid>
      <dc:creator>EiffelPalace</dc:creator>
      <dc:date>2024-01-02T20:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673061#M112743</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist3 = EventCode="4673" Process_Name=".*\\DesktopExtension\.exe.*"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;From what I'm reading on Splunk docs it seems that it needs to be a valid regex to work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dtburrows3_0-1704228189002.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28719i3320CF002114697C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dtburrows3_0-1704228189002.png" alt="dtburrows3_0-1704228189002.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This regex seems to match properly&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dtburrows3_1-1704228253623.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28720iDA6F1846BB2ACEF6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dtburrows3_1-1704228253623.png" alt="dtburrows3_1-1704228253623.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The original regex you posted doesn't seem to valid according to regex101&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dtburrows3_2-1704228307816.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28721i8E08859B793116C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dtburrows3_2-1704228307816.png" alt="dtburrows3_2-1704228307816.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also noticed that the Key you posted "ProcessName" is different then the field I see extracted on windows data on my local machine which is extracted as "Process_Name" but maybe that is how it is coming over in your environment. If that is the case then maybe this could work.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist3 = EventCode="4673" ProcessName=".*\\DesktopExtension\.exe.*"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Jan 2024 20:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673061#M112743</guid>
      <dc:creator>dtburrows3</dc:creator>
      <dc:date>2024-01-02T20:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673062#M112744</link>
      <description>&lt;P&gt;"ProcessName" is not a valid key for a blacklist setting.&amp;nbsp; Valid keys are "Category, CategoryString, ComputerName, EventCode, EventType, Keywords, LogName, Message, OpCode, RecordNumber, Sid, SidType, SourceName, TaskCategory, Type, and User".&lt;/P&gt;&lt;P&gt;Also, the RHS must be a valid regular expression.&amp;nbsp; A valid regex cannot begin with "*".&amp;nbsp; If you're trying to specify a wildcard at the beginning and end of the match then there's no need - that's implied with most regexes.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 20:50:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673062#M112744</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-02T20:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673063#M112745</link>
      <description>&lt;P&gt;Did not know about the valid key entries. Thanks for sharing!&lt;BR /&gt;Came across this documentation after reading your comment.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/MonitorWindowseventlogdata" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Oof and this right in inputs.conf docs&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dtburrows3_0-1704229620202.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28722i6AB3F1A95E4280FC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dtburrows3_0-1704229620202.png" alt="dtburrows3_0-1704229620202.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 21:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673063#M112745</guid>
      <dc:creator>dtburrows3</dc:creator>
      <dc:date>2024-01-02T21:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673142#M112752</link>
      <description>&lt;P&gt;I see that the desktopexetension.exe is also in the message so would something like this work?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist = EventCode=4673 message="DesktopExtension.exe"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is an example message:&lt;BR /&gt;A privileged service was called. Subject: Service: Server: Security Service Name: - Process: Process ID: 0x2fcc Process Name: C:\Program Files\WindowsApps\AD2F1837.myHP_26.52343.948.0_x64__v10z8vjag6ke6\win32\DesktopExtension.exe Service Request Information: Privileges: SeTcbPrivilege&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 15:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673142#M112752</guid>
      <dc:creator>EiffelPalace</dc:creator>
      <dc:date>2024-01-03T15:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Blacklist DesktopExtension.exe addition inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673147#M112753</link>
      <description>&lt;P&gt;Yes, that should work.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist = EventCode=4673 message="DesktopExtension\.exe"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 03 Jan 2024 16:21:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Blacklist-DesktopExtension-exe-addition-inputs-conf/m-p/673147#M112753</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-03T16:21:44Z</dc:date>
    </item>
  </channel>
</rss>

