<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble Ingesting Whitelisted Event Codes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-Ingesting-Whitelisted-Event-Codes/m-p/690392#M114875</link>
    <description>&lt;P&gt;It appears that only one of my hosts is sending in security logs - the Splunk search head.&amp;nbsp; Verified all other hosts have received the inputs.conf and are running with the required level of permissions.&amp;nbsp; Don't see any windows firewall events which are blocking the outbound connection.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 21:56:06 GMT</pubDate>
    <dc:creator>kymenope</dc:creator>
    <dc:date>2024-06-11T21:56:06Z</dc:date>
    <item>
      <title>Trouble Ingesting Whitelisted Event Codes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-Ingesting-Whitelisted-Event-Codes/m-p/690381#M114873</link>
      <description>&lt;P&gt;My inputs.conf looks like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index = wineventlog&lt;/P&gt;&lt;P&gt;sourcetype = WinEventLog:Security&lt;/P&gt;&lt;P&gt;disabled = 0&lt;/P&gt;&lt;P&gt;whitelist = 1, 2, 3, 4, 5&lt;/P&gt;&lt;P&gt;blacklist1 = $XmlRegex="(?ms)&amp;lt;EventID&amp;gt;5156&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data\sName='Application'&amp;gt;\\device\\harddiskvolume\d+\\program\sfiles\\splunkuniversalforwarder\\(bin\\splunkd\.exe|etc\\apps\\splunk_ta_stream\\windows_x86_64\\bin\\streamfwd\.exe)&amp;lt;.*&amp;lt;Data\sName='DestPort'&amp;gt;(9997|443|8000)&amp;lt;"&lt;BR /&gt;&lt;BR /&gt;blacklist2 = $XmlRegex="(?ms)&amp;lt;EventID&amp;gt;5156&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data\sName='DestAddress'&amp;gt;(127.0.0.1|::1|0:0:0:0:0:0:0:1|169.254.*?|fe80:.*?)&amp;lt;"&lt;BR /&gt;&lt;BR /&gt;blacklist3 = $XmlRegex="(?ms)&amp;lt;EventID&amp;gt;4688&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data\sName='NewProcessName'&amp;gt;C:\\Program Files\\SplunkUniversalForwarder\\(etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe|bin\\(splunk-powershell.exe|splunk-MonitorNoHandle.exe|splunk-netmon.exe|splunk-regmon.exe|splunkd.exe|btool.exe|splunk.exe|splunk-winevtlog.exe|splunk-admon.exe|splunk-perfmon.exe|splunk-winprintmon.exe|splunk-wmi.exe))&amp;lt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I confirmed that this config has been pushed to all forwarders, the forwarders are using the local system account, and that the firewall is not blocking anything.&amp;nbsp; Despite this the logs I am ingesting are unrelated to my explicit whitelist and are ~5% of what I am expecting to see.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:51:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-Ingesting-Whitelisted-Event-Codes/m-p/690381#M114873</guid>
      <dc:creator>kymenope</dc:creator>
      <dc:date>2024-06-11T22:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble Ingesting Whitelisted Event Codes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-Ingesting-Whitelisted-Event-Codes/m-p/690392#M114875</link>
      <description>&lt;P&gt;It appears that only one of my hosts is sending in security logs - the Splunk search head.&amp;nbsp; Verified all other hosts have received the inputs.conf and are running with the required level of permissions.&amp;nbsp; Don't see any windows firewall events which are blocking the outbound connection.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-Ingesting-Whitelisted-Event-Codes/m-p/690392#M114875</guid>
      <dc:creator>kymenope</dc:creator>
      <dc:date>2024-06-11T21:56:06Z</dc:date>
    </item>
  </channel>
</rss>

