<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter WinEventLog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84185#M17486</link>
    <description>&lt;P&gt;The props/transforms only apply when the events are parsed, so only on the indexers (or heavy forwarders)&lt;BR /&gt;
It will not work in the universal or lightweight forwarders.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2013 21:15:57 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-12-31T21:15:57Z</dc:date>
    <item>
      <title>Filter WinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84181#M17482</link>
      <description>&lt;P&gt;Hi, i need of the filter for Windows Logs, in Splunk Web, ok....more i need in inputs in each machine.&lt;BR /&gt;
TaskCategory="Logon" OR "logoff" Logon_Type="2" OR Logon_Type="3" OR Logon_Type="10" OR Logon_Type="11"&lt;/P&gt;

&lt;P&gt;thanks..&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84181#M17482</guid>
      <dc:creator>mildorp</dc:creator>
      <dc:date>2020-09-28T14:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Filter WinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84182#M17483</link>
      <description>&lt;P&gt;I'm not sure what you're asking for.  I tried the search below on our system and it works fine:&lt;/P&gt;

&lt;P&gt;index="main" (TaskCategory="Logon" OR TaskCategory="logoff") (Logon_Type="2" OR Logon_Type="3" OR Logon_Type="10" OR Logon_Type="11")&lt;/P&gt;

&lt;P&gt;Are you getting the events you want?  &lt;/P&gt;

&lt;P&gt;Note that your search:  TaskCategory="Logon" OR "logoff" will get any events that contain the work "logoff", even if they are not in the TaskCategory field.  &lt;/P&gt;

&lt;P&gt;You might want to use (TaskCategory="Logon" OR TaskCategory="logoff")&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84182#M17483</guid>
      <dc:creator>Jon_Webster</dc:creator>
      <dc:date>2020-09-28T14:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Filter WinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84183#M17484</link>
      <description>&lt;P&gt;Thanks...&lt;BR /&gt;
I need to use this filter in transforms.conf and propos.conf the file, however it's not working.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84183#M17484</guid>
      <dc:creator>mildorp</dc:creator>
      <dc:date>2013-07-04T11:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Filter WinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84184#M17485</link>
      <description>&lt;P&gt;Thanks...&lt;BR /&gt;
I need to use this filter in transforms.conf and propos.conf the file, however it's not working.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84184#M17485</guid>
      <dc:creator>mildorp</dc:creator>
      <dc:date>2013-07-04T11:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Filter WinEventLog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84185#M17486</link>
      <description>&lt;P&gt;The props/transforms only apply when the events are parsed, so only on the indexers (or heavy forwarders)&lt;BR /&gt;
It will not work in the universal or lightweight forwarders.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2013 21:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-WinEventLog/m-p/84185#M17486</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-12-31T21:15:57Z</dc:date>
    </item>
  </channel>
</rss>

