<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue filtering events from windows secutiry log going into indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-filtering-events-from-windows-secutiry-log-going-into/m-p/177178#M35518</link>
    <description>&lt;P&gt;I am having difficulty filtering the Windows security logs. I have attempted to restrict the event IDs being sent but at the moment the entire security log is being indexed.  Here is my currently deployed configuration. Any help would be greatly appreciated. &lt;/P&gt;

&lt;P&gt;Inputs.conf&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled=0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;/P&gt;

&lt;P&gt;index = security&lt;/P&gt;

&lt;P&gt;[WinEventLog:rDirectory]&lt;BR /&gt;
disabled=0&lt;/P&gt;

&lt;P&gt;Props.conf&lt;/P&gt;

&lt;P&gt;[source::WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-set= setnull,setparsing,setparsing2&lt;/P&gt;

&lt;P&gt;Transforms.conf&lt;/P&gt;

&lt;P&gt;[setnull]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue &lt;/P&gt;

&lt;P&gt;[setparsing]&lt;BR /&gt;
REGEX=(?m)^EventCode=&lt;BR /&gt;
(530|531|532|533|534|535|536|537|529|560|566|624|626|627|628|629|630|631|632|633|634|635|636|637|638|639|640|641|642|643|644|645|646|647|648|649|650|651|652|653|654|655|656|657|658|659|660|661|662|663|664|665|666|667|668|669|670|671|675|676|681|684|685|686|687|688|689|690|691|692|693|694|695|696|697|4625|4648|4656|4662|4706|4707|4713|4720|4723|4724|4725|4726|4727|4728|4729|4730|4731|4732|4733|4734|4735|4737|4738|4739|4740|4754|4755|4756|4757|4758|4767|4768|4771|4776|4780|4781|4786|4787|4788|4789|4790|4791|5136|5137)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;

&lt;P&gt;[setparsing2]&lt;BR /&gt;
REGEX=(?m)^Accesses=&lt;BR /&gt;
(ListAccounts|DELETE|WRITE_DAC|WRITE_OWNER|WritePreferences|WriteAccount|SetPassword)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 16:42:56 GMT</pubDate>
    <dc:creator>briandickinson</dc:creator>
    <dc:date>2020-09-28T16:42:56Z</dc:date>
    <item>
      <title>Issue filtering events from windows secutiry log going into indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-filtering-events-from-windows-secutiry-log-going-into/m-p/177178#M35518</link>
      <description>&lt;P&gt;I am having difficulty filtering the Windows security logs. I have attempted to restrict the event IDs being sent but at the moment the entire security log is being indexed.  Here is my currently deployed configuration. Any help would be greatly appreciated. &lt;/P&gt;

&lt;P&gt;Inputs.conf&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled=0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;/P&gt;

&lt;P&gt;index = security&lt;/P&gt;

&lt;P&gt;[WinEventLog:rDirectory]&lt;BR /&gt;
disabled=0&lt;/P&gt;

&lt;P&gt;Props.conf&lt;/P&gt;

&lt;P&gt;[source::WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-set= setnull,setparsing,setparsing2&lt;/P&gt;

&lt;P&gt;Transforms.conf&lt;/P&gt;

&lt;P&gt;[setnull]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue &lt;/P&gt;

&lt;P&gt;[setparsing]&lt;BR /&gt;
REGEX=(?m)^EventCode=&lt;BR /&gt;
(530|531|532|533|534|535|536|537|529|560|566|624|626|627|628|629|630|631|632|633|634|635|636|637|638|639|640|641|642|643|644|645|646|647|648|649|650|651|652|653|654|655|656|657|658|659|660|661|662|663|664|665|666|667|668|669|670|671|675|676|681|684|685|686|687|688|689|690|691|692|693|694|695|696|697|4625|4648|4656|4662|4706|4707|4713|4720|4723|4724|4725|4726|4727|4728|4729|4730|4731|4732|4733|4734|4735|4737|4738|4739|4740|4754|4755|4756|4757|4758|4767|4768|4771|4776|4780|4781|4786|4787|4788|4789|4790|4791|5136|5137)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;

&lt;P&gt;[setparsing2]&lt;BR /&gt;
REGEX=(?m)^Accesses=&lt;BR /&gt;
(ListAccounts|DELETE|WRITE_DAC|WRITE_OWNER|WritePreferences|WriteAccount|SetPassword)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-filtering-events-from-windows-secutiry-log-going-into/m-p/177178#M35518</guid>
      <dc:creator>briandickinson</dc:creator>
      <dc:date>2020-09-28T16:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue filtering events from windows secutiry log going into indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-filtering-events-from-windows-secutiry-log-going-into/m-p/177179#M35519</link>
      <description>&lt;P&gt;Any chance you are on splunk 6?&lt;/P&gt;

&lt;P&gt;You can filter event codes at the forwarders now.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowsdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowsdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 May 2014 19:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-filtering-events-from-windows-secutiry-log-going-into/m-p/177179#M35519</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2014-05-25T19:13:42Z</dc:date>
    </item>
  </channel>
</rss>

