<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ingest actions/nullQueue not working for some Windows multiline events. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683315#M114073</link>
    <description>&lt;P&gt;I'm trying to remove some Windows events from being ingested ... example below:&lt;BR /&gt;&lt;BR /&gt;The regex I've tried in both Ingest Actions and the old method works both at regex101 and in my SPL&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;index=win* EventCode=4103 Message=*Files\\SplunkUniversalForwarder* &lt;BR /&gt;| regex "EventCode=4103(.|\r|\n)+\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yet, when I configure an ingest action ruleset, nothing gets removed. &lt;BR /&gt;&lt;SPAN class=""&gt;[_rule:ruleset_WinEventLogSecurity:filter:regex:ft7j3fkn]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;INGEST_EVAL = queue=if(match(_raw, "EventCode=4103(.|\\r|\\n)+\\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1"), "nullQueue", queue)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;STOP_PROCESSING_IF = queue == "nullQueue"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;same goes for trying to do it "the old way"&lt;BR /&gt;&lt;BR /&gt;[drop_4103_splunkpowershell]&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;REGEX = EventCode=4103(.|\r|\n)+\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1&lt;BR /&gt;FORMAT = nullQueue&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;04/04/2024 07:02:28 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;LogName=Microsoft-Windows-PowerShell/Operational&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EventCode=4103&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EventType=4&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ComputerName=redacted&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Sid=S-1-5-18&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SidType=0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SourceName=Microsoft-Windows-PowerShell&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Type=Information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RecordNumber=1258288151&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Keywords=None&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TaskCategory=Executing Pipeline&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;OpCode=To be used when operation is just executing a method&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Message=CommandInvocation(Start-Sleep): "Start-Sleep"&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ParameterBinding(Start-Sleep): name="Milliseconds"; value="200"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Context:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Severity = Informational&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Name = ConsoleHost&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Version = 5.1.17763.5576&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host ID = 222d8490-3c1f-486d-94ed-47f91e59da32&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Application = powershell.exe -command $input |C:\Program` Files\SplunkUniversalForwarder\bin\splunk-powershell.ps1 C:\Program` Files\SplunkUniversalForwarder e20c0be00a8583fe&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Engine Version = 5.1.17763.5576&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Runspace ID = 87084a50-365f-409b-aed6-d666c6c6b2b&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Pipeline ID = 1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Command Name = Start-Sleep&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Command Type = Cmdlet&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Script Name = .......&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2024 20:15:41 GMT</pubDate>
    <dc:creator>gazoscreek</dc:creator>
    <dc:date>2024-04-04T20:15:41Z</dc:date>
    <item>
      <title>Ingest actions/nullQueue not working for some Windows multiline events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683315#M114073</link>
      <description>&lt;P&gt;I'm trying to remove some Windows events from being ingested ... example below:&lt;BR /&gt;&lt;BR /&gt;The regex I've tried in both Ingest Actions and the old method works both at regex101 and in my SPL&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;index=win* EventCode=4103 Message=*Files\\SplunkUniversalForwarder* &lt;BR /&gt;| regex "EventCode=4103(.|\r|\n)+\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yet, when I configure an ingest action ruleset, nothing gets removed. &lt;BR /&gt;&lt;SPAN class=""&gt;[_rule:ruleset_WinEventLogSecurity:filter:regex:ft7j3fkn]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;INGEST_EVAL = queue=if(match(_raw, "EventCode=4103(.|\\r|\\n)+\\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1"), "nullQueue", queue)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;STOP_PROCESSING_IF = queue == "nullQueue"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;same goes for trying to do it "the old way"&lt;BR /&gt;&lt;BR /&gt;[drop_4103_splunkpowershell]&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;REGEX = EventCode=4103(.|\r|\n)+\s+Files.SplunkUniversalForwarder.bin.splunk-powershell.ps1&lt;BR /&gt;FORMAT = nullQueue&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;04/04/2024 07:02:28 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;LogName=Microsoft-Windows-PowerShell/Operational&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EventCode=4103&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;EventType=4&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ComputerName=redacted&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;User=NOT_TRANSLATED&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Sid=S-1-5-18&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SidType=0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;SourceName=Microsoft-Windows-PowerShell&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Type=Information&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RecordNumber=1258288151&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Keywords=None&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;TaskCategory=Executing Pipeline&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;OpCode=To be used when operation is just executing a method&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Message=CommandInvocation(Start-Sleep): "Start-Sleep"&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ParameterBinding(Start-Sleep): name="Milliseconds"; value="200"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Context:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Severity = Informational&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Name = ConsoleHost&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Version = 5.1.17763.5576&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host ID = 222d8490-3c1f-486d-94ed-47f91e59da32&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Host Application = powershell.exe -command $input |C:\Program` Files\SplunkUniversalForwarder\bin\splunk-powershell.ps1 C:\Program` Files\SplunkUniversalForwarder e20c0be00a8583fe&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Engine Version = 5.1.17763.5576&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Runspace ID = 87084a50-365f-409b-aed6-d666c6c6b2b&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Pipeline ID = 1&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Command Name = Start-Sleep&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Command Type = Cmdlet&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Script Name = .......&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 20:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683315#M114073</guid>
      <dc:creator>gazoscreek</dc:creator>
      <dc:date>2024-04-04T20:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest actions/nullQueue not working for some Windows multiline events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683327#M114074</link>
      <description>&lt;P&gt;IME, \r and \n don't always work in Splunk regexes.&amp;nbsp; To match any text that might include newlines, try &lt;FONT face="courier new,courier"&gt;[\s\S]+&lt;/FONT&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EventCode=4103[\s\S]+\s+Files\\SplunkUniversalForwarder\\bin\\splunk-powershell\.ps1&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 04 Apr 2024 20:23:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683327#M114074</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-04T20:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ingest actions/nullQueue not working for some Windows multiline events.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683330#M114075</link>
      <description>&lt;P&gt;Thank you kindly ... this worked perfectly.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 20:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingest-actions-nullQueue-not-working-for-some-Windows-multiline/m-p/683330#M114075</guid>
      <dc:creator>gazoscreek</dc:creator>
      <dc:date>2024-04-04T20:53:52Z</dc:date>
    </item>
  </channel>
</rss>

