<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter Windows Security events by changing inputs conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140853#M28844</link>
    <description>&lt;P&gt;Hello there,&lt;/P&gt;

&lt;P&gt;Have you tried using &lt;CODE&gt;blacklist&lt;/CODE&gt; instead of &lt;CODE&gt;whitelist&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;There's a good blog you can read here: &lt;A href="http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/"&gt;http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Apr 2015 13:21:41 GMT</pubDate>
    <dc:creator>kendrickt</dc:creator>
    <dc:date>2015-04-10T13:21:41Z</dc:date>
    <item>
      <title>How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140852#M28843</link>
      <description>&lt;P&gt;I  have made the following changes in my inputs.conf. However no luck&lt;BR /&gt;
Could anyone help me with this?&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
ignoreOlderThan=24h&lt;BR /&gt;
recursive=false&lt;BR /&gt;
disabled=false&lt;BR /&gt;
whitelist=1100-1102,1104,1105,1108,4608-4612,4614-4616,4618,4621,4622,4624-4626,4634,4646-4668,4670-4673,4675,4688-4702,4704-4707,4709-4720,4722-4735,4737-4794,4797,4800-4803,4816-4824,4864-4900,4902,4904-4913,4928-4937,4944-4954,4956-4958,4960-4965,4976-4985,5024,5025,5027-5035,5037-5051,5056-5071,5120-5127,5136-5159,5168,5376-5378,5440-5444,5446-5453,5456-5468,5471-5474,5477-5480,5483-5485,5632,5633,5712,5888-5890,6144,6145,6272-6281,6400-6409&lt;BR /&gt;
index=indexname&lt;BR /&gt;
sourcetype=sourcetypename&lt;/P&gt;

&lt;P&gt;However the above whitelist filter did not work at all. Specifically I dont want Eventcode 4674 events. So I have omitted it in whitelist.But events with 4674 are not getting filtered.&lt;/P&gt;

&lt;P&gt;Possible tries:&lt;/P&gt;

&lt;P&gt;Do I need to specify blacklist?&lt;BR /&gt;
Do I mention like this "Eventcode=4566" ?&lt;BR /&gt;
Do I use anyother stanza to achieve this?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2015 12:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140852#M28843</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2015-04-10T12:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140853#M28844</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;

&lt;P&gt;Have you tried using &lt;CODE&gt;blacklist&lt;/CODE&gt; instead of &lt;CODE&gt;whitelist&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;There's a good blog you can read here: &lt;A href="http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/"&gt;http://blogs.splunk.com/2013/10/14/windows-event-logs-in-splunk-6/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2015 13:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140853#M28844</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-04-10T13:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140854#M28845</link>
      <description>&lt;P&gt;Many thanks for the reply.&lt;/P&gt;

&lt;P&gt;Yes. I have tried both whitelist and blacklist. &lt;BR /&gt;
Still the filter did not work.&lt;BR /&gt;
I have also tried to include evt_resolve_ad_obj = 1 in my inputs.conf.&lt;BR /&gt;
However that also doesn't seem to work.&lt;BR /&gt;
Could anyone please suggest any other possibilities to filter events based on event codes?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140854#M28845</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2020-09-28T19:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140855#M28846</link>
      <description>&lt;P&gt;Same problem..  whitelisting doesn't work.  I would think that if you whitelist certain events everything else is blocked but not working for me either.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2016 01:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140855#M28846</guid>
      <dc:creator>mendesjo</dc:creator>
      <dc:date>2016-02-13T01:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140856#M28847</link>
      <description>&lt;P&gt;As you've not mentioned it, did you check that the UF installed on that machine is actually version 6?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 22:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140856#M28847</guid>
      <dc:creator>laurie_gellatly</dc:creator>
      <dc:date>2016-02-24T22:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows Security events by changing inputs conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140857#M28848</link>
      <description>&lt;P&gt;Found my problem.. between events I had one entry with two commas in a row, which made it not work.. all good.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 23:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-Security-events-by-changing-inputs-conf/m-p/140857#M28848</guid>
      <dc:creator>mendesjo</dc:creator>
      <dc:date>2016-02-24T23:10:03Z</dc:date>
    </item>
  </channel>
</rss>

