<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter Windows event logs from a Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22605#M3510</link>
    <description>&lt;P&gt;Your question title announces the question is regarding filtering the events on a UF, so...&lt;/P&gt;

&lt;P&gt;If you want help with the specific details you need to provide us with more information than that it "didn't work" - it's impossible to know exactly what you tried and what the exact result was. General info on event filtering is available here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2013 17:37:57 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-05-02T17:37:57Z</dc:date>
    <item>
      <title>How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22601#M3506</link>
      <description>&lt;P&gt;Using 5.0.2. I am receiving Windows Event Logs at the Indexer from Universal Forwarders on Windows servers. I want to filter out or send to a null queue uninteresting Windows events, so I only see Error, Warning and Critical events. &lt;/P&gt;

&lt;P&gt;I know this needs to be in the props.conf and transforms.conf but can't get it to work.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22601#M3506</guid>
      <dc:creator>mokeefe</dc:creator>
      <dc:date>2013-05-02T17:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22602#M3507</link>
      <description>&lt;P&gt;You cannot filter events on a Universal Forwarder. Event filtering can only occur on Splunk instances that perform parsing, which Universal Forwarder doesn't (and can't) do. You need to either setup filtering on the indexer, or switch to a heavy forwarder instead of a Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22602#M3507</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-02T17:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22603#M3508</link>
      <description>&lt;P&gt;Yes, I know I can't do it at the UF, but I want to drop the events on the Indexer before they get indexed.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22603#M3508</guid>
      <dc:creator>mokeefe</dc:creator>
      <dc:date>2013-05-02T17:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22604#M3509</link>
      <description>&lt;P&gt;Yes, I know I can't do it at the UF, but I want to drop the events on the Indexer before they get indexed.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22604#M3509</guid>
      <dc:creator>mokeefe</dc:creator>
      <dc:date>2013-05-02T17:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22605#M3510</link>
      <description>&lt;P&gt;Your question title announces the question is regarding filtering the events on a UF, so...&lt;/P&gt;

&lt;P&gt;If you want help with the specific details you need to provide us with more information than that it "didn't work" - it's impossible to know exactly what you tried and what the exact result was. General info on event filtering is available here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:37:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22605#M3510</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-02T17:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter Windows event logs from a Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22606#M3511</link>
      <description>&lt;P&gt;Check out new Windows Event Log capabilities in Splunk 6.1:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2014/05/23/controlling-4662-messages-in-the-windows-security-event-log/"&gt;http://blogs.splunk.com/2014/05/23/controlling-4662-messages-in-the-windows-security-event-log/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 18:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-Windows-event-logs-from-a-Universal-Forwarder/m-p/22606#M3511</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2014-10-31T18:03:09Z</dc:date>
    </item>
  </channel>
</rss>

