<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discard Windows Events and keep the rest in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16852#M2069</link>
    <description>&lt;P&gt;Not sure if anything yet but tried shifting the configuration to the forwarder itself now as mine seems to be a heavy forwarder.&lt;/P&gt;

&lt;P&gt;Found this link to be useful:
&lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F" rel="nofollow"&gt;Where do I configure my Splunk settings?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Seems ok but am monitoring it.If it works, it solves my problem of filtering out event codes on one server but not another as well..&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2010 15:42:31 GMT</pubDate>
    <dc:creator>apro</dc:creator>
    <dc:date>2010-07-05T15:42:31Z</dc:date>
    <item>
      <title>Discard Windows Events and keep the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16851#M2068</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Had installed splunk on serverA and serverB and configured both as a forwarder to forward wineventlogs to splunk indexer.&lt;/P&gt;

&lt;P&gt;I will like to filter out certain events(eg.540) and I tried doing this on the splunk indexer itself:  &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;/opt/splunk/etc/system/local/props.conf&lt;BR /&gt;
 [WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-null = setnull&lt;/CODE&gt;  &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;/opt/splunk/etc/system/local/transforms.conf&lt;BR /&gt;
 [setnull]&lt;BR /&gt;
REGEX = (?m)^EventCode=540&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue
&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;Apparently it still doesn't work after doing a search the events are still shown:&lt;BR /&gt;
host="serverA" EventCode=540 &lt;/P&gt;

&lt;P&gt;1) How do I filter out event code 540? Should it be done on the forwarder itself or splunk indexer?&lt;/P&gt;

&lt;P&gt;2) How do I filter out event code 540, only on serverA and not serverB?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2010 11:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16851#M2068</guid>
      <dc:creator>apro</dc:creator>
      <dc:date>2010-07-05T11:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Discard Windows Events and keep the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16852#M2069</link>
      <description>&lt;P&gt;Not sure if anything yet but tried shifting the configuration to the forwarder itself now as mine seems to be a heavy forwarder.&lt;/P&gt;

&lt;P&gt;Found this link to be useful:
&lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F" rel="nofollow"&gt;Where do I configure my Splunk settings?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Seems ok but am monitoring it.If it works, it solves my problem of filtering out event codes on one server but not another as well..&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2010 15:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16852#M2069</guid>
      <dc:creator>apro</dc:creator>
      <dc:date>2010-07-05T15:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Discard Windows Events and keep the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16853#M2070</link>
      <description>&lt;P&gt;Did this ever start working for you?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 03:50:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16853#M2070</guid>
      <dc:creator>aaronzabell</dc:creator>
      <dc:date>2010-08-24T03:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Discard Windows Events and keep the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16854#M2071</link>
      <description>&lt;P&gt;I've had the same problem. I can filter perfmon this way. I have a mix of heavy/universal forwarders and don't want to implement the filter on every windows heavy forwarder individually.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2013 12:31:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Discard-Windows-Events-and-keep-the-rest/m-p/16854#M2071</guid>
      <dc:creator>mgh4</dc:creator>
      <dc:date>2013-07-12T12:31:42Z</dc:date>
    </item>
  </channel>
</rss>

