<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to blacklist Windows security events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110607#M23222</link>
    <description>&lt;P&gt;Hi @kpavan&lt;/P&gt;

&lt;P&gt;Correct me if I'm wrong, but from your post and this most recent comment, it sounds like you only configured inputs.conf on the indexer? I read through the comments thread on that blog and the writer states in the 2nd to last comment that this configuration works on the forwarder.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Sep 2014 17:51:49 GMT</pubDate>
    <dc:creator>ppablo</dc:creator>
    <dc:date>2014-09-04T17:51:49Z</dc:date>
    <item>
      <title>How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110604#M23219</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We are running splunk-6.0.3-204106 version, now we are seeing high Splunk license usage from Windows Security events. So I would like to block these events. I tried below blacklist with ref blog but its not filtering any events. Please help me on how to fix this issue.&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
blacklist = 4720, 4722, 4723, 4724, 4725, 4726, 4719, 4734, 4735, 4737, 4897, 4738, 4782, 4749, 4625, 4771, 4624&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 06:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110604#M23219</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2014-09-04T06:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110605#M23220</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I guess you used this post to help: &lt;A href="http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/"&gt;http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;It looks correct.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Did you push this config on your Indexer AND Forwarder ?&lt;/LI&gt;
&lt;LI&gt;Did you restart your servers ?&lt;/LI&gt;
&lt;LI&gt;Do you have another stanza about WinEventLog that can overwrite this one ?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 04 Sep 2014 07:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110605#M23220</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-09-04T07:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110606#M23221</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I did configured on indexer inputs.conf and restarted the servers as well. And there are no stanza in indexer to overwrite this one.&lt;/P&gt;

&lt;P&gt;i just have below configs in indexer, is there any mistake in my configs.&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = splunk-index-dev-1&lt;/P&gt;

&lt;P&gt;[WinEventLog:System]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
blacklist = 7036&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 10:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110606#M23221</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2014-09-04T10:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110607#M23222</link>
      <description>&lt;P&gt;Hi @kpavan&lt;/P&gt;

&lt;P&gt;Correct me if I'm wrong, but from your post and this most recent comment, it sounds like you only configured inputs.conf on the indexer? I read through the comments thread on that blog and the writer states in the 2nd to last comment that this configuration works on the forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 17:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110607#M23222</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-09-04T17:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110608#M23223</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Sorry for the delay in response!&lt;/P&gt;

&lt;P&gt;Yes, I have configured on indexer server. Now I got to know this configure works on Universal forwarder only. Sorry for my mistake.&lt;/P&gt;

&lt;P&gt;Could you please let me know how to block from indexer level, because I have 300+ host's sending the logs to splunk and it is eating my license very much.&lt;/P&gt;

&lt;P&gt;Please help me on this issue.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2014 17:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110608#M23223</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2014-09-08T17:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110609#M23224</link>
      <description>&lt;P&gt;So you don't have any forwarder on your 300 hosts?&lt;/P&gt;

&lt;P&gt;If you have a distributed environment and a forwarder on every host, you can easily create a configuration to push on all your hosts using serverclass.conf.&lt;/P&gt;

&lt;P&gt;If you receive your data directly on a port (like 9997), it works the same way: In your stanza that applies just add the blacklist feature.&lt;/P&gt;

&lt;P&gt;Is it helpful?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 09:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110609#M23224</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-09-09T09:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110610#M23225</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have UF installed all 300 servers and all the 300 windows serves are sending the security logs, so now i wanted to put a blacklist on indexer to block the all the logs which are coming. Since configuring on all the UF will be time consuming. Please suggest me with configurations how can achieve this task.&lt;/P&gt;

&lt;P&gt;And also help me, if I want to block the specific IP can I block on indexer?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 13:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110610#M23225</guid>
      <dc:creator>kpavan</dc:creator>
      <dc:date>2014-09-09T13:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110611#M23226</link>
      <description>&lt;P&gt;Hum I can't help on this specific need sorry.&lt;/P&gt;

&lt;P&gt;My only solution is: Deployment Server&lt;BR /&gt;
I would create an application with the stanza that blacklist EventCodes. Then use the deployment feature of Splunk to push this application on all my forwarders.&lt;BR /&gt;
You need a licence to create a deployment server&lt;/P&gt;

&lt;P&gt;Doc: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Updating/Extendedexampledeployseveralstandardforwarders"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Updating/Extendedexampledeployseveralstandardforwarders&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Deploy:DeploymentServer"&gt;http://wiki.splunk.com/Deploy:DeploymentServer&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 13:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110611#M23226</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-09-09T13:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to blacklist Windows security events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110612#M23227</link>
      <description>&lt;P&gt;If you want to block a specific IP or a host you can also use the nullqueue instead of blacklist.&lt;BR /&gt;
It simple to configure: &lt;A href="http://answers.splunk.com/answers/59370/filtering-events-using-nullqueue"&gt;http://answers.splunk.com/answers/59370/filtering-events-using-nullqueue&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2014 13:38:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-blacklist-Windows-security-events/m-p/110612#M23227</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2014-09-09T13:38:30Z</dc:date>
    </item>
  </channel>
</rss>

