<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarder Pulling Windows events: blacklist not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162021#M32885</link>
    <description>&lt;P&gt;This looks all good to me (you do not need the &lt;CODE&gt;disabled&lt;/CODE&gt; line at all, BTW); did you restart your Splunk instances on your Forwarders?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2015 22:25:05 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-08-05T22:25:05Z</dc:date>
    <item>
      <title>Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162020#M32884</link>
      <description>&lt;P&gt;Blacklists and suppress_text in Splunk 6.2.4 are not working for me on a heavy forwarder.&lt;/P&gt;

&lt;P&gt;my inputs.conf is:&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
blacklist = 5152-5158&lt;BR /&gt;
suppress_text = 1&lt;BR /&gt;
...&lt;/P&gt;

&lt;P&gt;And I've also tried &lt;/P&gt;

&lt;P&gt;[WMI:WinEventLog:Security]&lt;BR /&gt;
blacklist = 5156-5158&lt;BR /&gt;
disabled = false&lt;BR /&gt;
suppress_text = 1&lt;/P&gt;

&lt;P&gt;and many variations on the source. The blacklist and suppress_text are doing nothing. I still get firewall events I don't want to see.&lt;/P&gt;

&lt;P&gt;Suggestions please.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162020#M32884</guid>
      <dc:creator>klutzen</dc:creator>
      <dc:date>2020-09-29T06:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162021#M32885</link>
      <description>&lt;P&gt;This looks all good to me (you do not need the &lt;CODE&gt;disabled&lt;/CODE&gt; line at all, BTW); did you restart your Splunk instances on your Forwarders?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 22:25:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162021#M32885</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-05T22:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162022#M32886</link>
      <description>&lt;P&gt;That's just it: I'm using the Heavy Forwarder to pull the logs via WMI from the Windows machines. There are no other forwarders.  It appears that when pulling from WMI only, blacklist and the suppress_text aren't available. I will see what the universal forwarder does in a bit.&lt;/P&gt;

&lt;P&gt;Thanks for the comment though.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 22:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162022#M32886</guid>
      <dc:creator>klutzen</dc:creator>
      <dc:date>2015-08-05T22:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162023#M32887</link>
      <description>&lt;P&gt;Restarting splunk in a command prompt:  Invalid key stanza for the blacklist line&lt;/P&gt;

&lt;P&gt;Well, now I know why its not working. It's being ignored.&lt;/P&gt;

&lt;P&gt;Now how do I fix it?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 23:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162023#M32887</guid>
      <dc:creator>klutzen</dc:creator>
      <dc:date>2015-08-05T23:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162024#M32888</link>
      <description>&lt;P&gt;Added the Splunk for windows add-on. Ok blacklist stanza error is now gone. Blacklist in inputs.conf&lt;/P&gt;

&lt;P&gt;is&lt;BR /&gt;
  [WinEventLog://Security]&lt;BR /&gt;
  blacklist = 5156-5158&lt;/P&gt;

&lt;P&gt;Accepted, but not working. Logs come through. Suspect it's because I'm pulling via WMI and its bypassing the rule&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 00:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162024#M32888</guid>
      <dc:creator>klutzen</dc:creator>
      <dc:date>2015-08-06T00:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162025#M32889</link>
      <description>&lt;P&gt;It would help if you posted the exact error log text but if it is as you are saying then my guess is that you are using an older version of splunk that does not support that blacklist format.  I say this because the documentation for the latest version of Splunk &lt;EM&gt;clearly&lt;/EM&gt; supports it:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Monitorwindowsdata#Use_the_Security_event_log_to_monitor_changes_to_files"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Monitorwindowsdata#Use_the_Security_event_log_to_monitor_changes_to_files&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Either that or you do not have a proper Heavy Forwarder binary installed (maybe Splunk makes the Universal/Light Forwarder treat incompatible settings as though they are nonsensical, which is what this log is saying).&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 02:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162025#M32889</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-06T02:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder Pulling Windows events: blacklist not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162026#M32890</link>
      <description>&lt;P&gt;Well, you clearly missed that I was running 6.2.4. Unless there is a secret version, it clearly does not work with 6.2.4 and the Heavy Forwarder pulling the logs from the Windows systems and applying the blacklist rules. Something is wrong here. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 04:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-Pulling-Windows-events-blacklist-not-working/m-p/162026#M32890</guid>
      <dc:creator>klutzen</dc:creator>
      <dc:date>2015-08-06T04:38:04Z</dc:date>
    </item>
  </channel>
</rss>

