<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Event Log Blacklist not Blacklisting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171967#M34670</link>
    <description>&lt;P&gt;I'm running Splunk 6.1 as my indexer. I have a 6.1 universal forwarder setup on a windows box and I'm trying to filter what event logs get sent back to the indexer.&lt;/P&gt;

&lt;P&gt;I added this stanza to inputs.conf in C:\Program Files\SplunkUniversalForwarder\etc\system\local:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
blacklist = 5145,5156&lt;/P&gt;

&lt;P&gt;I then restarted the forwarder service and unfortunately I am still seeing 5145s and 5156s in my indexer. Am I missing something? I looked at splunkd.log but it didn't provide any insight on the issue.&lt;/P&gt;

&lt;P&gt;Josh&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2014 20:58:09 GMT</pubDate>
    <dc:creator>jadams7325</dc:creator>
    <dc:date>2014-08-05T20:58:09Z</dc:date>
    <item>
      <title>Windows Event Log Blacklist not Blacklisting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171967#M34670</link>
      <description>&lt;P&gt;I'm running Splunk 6.1 as my indexer. I have a 6.1 universal forwarder setup on a windows box and I'm trying to filter what event logs get sent back to the indexer.&lt;/P&gt;

&lt;P&gt;I added this stanza to inputs.conf in C:\Program Files\SplunkUniversalForwarder\etc\system\local:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
blacklist = 5145,5156&lt;/P&gt;

&lt;P&gt;I then restarted the forwarder service and unfortunately I am still seeing 5145s and 5156s in my indexer. Am I missing something? I looked at splunkd.log but it didn't provide any insight on the issue.&lt;/P&gt;

&lt;P&gt;Josh&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 20:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171967#M34670</guid>
      <dc:creator>jadams7325</dc:creator>
      <dc:date>2014-08-05T20:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Log Blacklist not Blacklisting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171968#M34671</link>
      <description>&lt;P&gt;Take a look at this excellent blog post:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2014/05/23/controlling-4662-messages-in-the-windows-security-event-log/"&gt;http://blogs.splunk.com/2014/05/23/controlling-4662-messages-in-the-windows-security-event-log/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 21:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171968#M34671</guid>
      <dc:creator>Jeff_Lightly_Sp</dc:creator>
      <dc:date>2014-08-05T21:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Event Log Blacklist not Blacklisting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171969#M34672</link>
      <description>&lt;P&gt;This blog is a good read. Other references&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/29218/filtering-windows-event-logs"&gt;http://answers.splunk.com/answers/29218/filtering-windows-event-logs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/136559/filtering-wineventlogsecurity"&gt;http://answers.splunk.com/answers/136559/filtering-wineventlogsecurity&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;They may have some extra filters, so adjust per your need.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 21:21:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Event-Log-Blacklist-not-Blacklisting/m-p/171969#M34672</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-05T21:21:46Z</dc:date>
    </item>
  </channel>
</rss>

