<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: filter WinEventLog:Security by Account Name in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25310#M4089</link>
    <description>&lt;P&gt;I've finally gotten this to work on my own.&lt;/P&gt;

&lt;P&gt;A few things changed.  &lt;/P&gt;

&lt;P&gt;1) I upgraded to the newest version of Splunk&lt;BR /&gt;
2) I changed the regex statement to be just regex = splunkrdba&lt;BR /&gt;
3) I change transforms.conf to be FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;I believe the 1st didn't really do much, but I wanted to mention it.  I think the second one finally caught what I wanted without catching anything else, and I believe the capital Q is necessary.  Hope this helps someone else.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Feb 2013 18:23:19 GMT</pubDate>
    <dc:creator>jturnerrdba</dc:creator>
    <dc:date>2013-02-11T18:23:19Z</dc:date>
    <item>
      <title>filter WinEventLog:Security by Account Name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25308#M4087</link>
      <description>&lt;P&gt;I'm running  Splunk 5.0 build 140868 on a Windows 2008 R2 server.  I'm trying to Audit file and folder deletes on this server, but the appropriate way to do this is to log for everyone.  My Splunk service account, splunkrdba, makes changes to it's logs constantly, so I want to send these events to the null queue, but I'm having issues with the Regex.  Below see my most recent props.conf, transforms.conf, and a sample log that I'm trying to prevent.&lt;/P&gt;

&lt;P&gt;Props.conf&lt;BR /&gt;
[WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-wmi= wminull&lt;/P&gt;

&lt;P&gt;Transforms.conf&lt;BR /&gt;
[wminull]&lt;BR /&gt;
REGEX = (?msi)^Accoung_Name=splunkrdba&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullqueue&lt;/P&gt;

&lt;P&gt;02/08/2013 09:32:55 AM&lt;BR /&gt;
LogName=Security&lt;BR /&gt;
SourceName=Microsoft Windows security auditing.&lt;BR /&gt;
EventCode=4660&lt;BR /&gt;
EventType=0&lt;BR /&gt;
Type=Information&lt;BR /&gt;
ComputerName= X&lt;BR /&gt;
TaskCategory=File System&lt;BR /&gt;
OpCode=Info&lt;BR /&gt;
RecordNumber=3184693&lt;BR /&gt;
Keywords=Audit Success&lt;BR /&gt;
Message=An object was deleted.&lt;/P&gt;

&lt;P&gt;Subject:&lt;BR /&gt;
    Security ID:        RDBA\splunkrdba&lt;BR /&gt;
    Account Name:       splunkrdba&lt;BR /&gt;
    Account Domain:     RDBA&lt;BR /&gt;
    Logon ID:       0xb8bbf7&lt;/P&gt;

&lt;P&gt;Object:&lt;BR /&gt;
    Object Server:  Security&lt;BR /&gt;
    Handle ID:  0x64&lt;/P&gt;

&lt;P&gt;Process Information:&lt;BR /&gt;
    Process ID: 0x1b00&lt;BR /&gt;
    Process Name:   C:\Program Files\Splunk\bin\splunk-optimize.exe&lt;BR /&gt;
    Transaction ID: {00000000-0000-0000-0000-000000000000}&lt;/P&gt;

&lt;P&gt;Collapse back to 10 lines&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=RDBALOG-002   Options|  
sourcetype=WinEventLog:Security   Options|  
source=WinEventLog:Security   Options
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:16:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25308#M4087</guid>
      <dc:creator>jturnerrdba</dc:creator>
      <dc:date>2020-09-28T13:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: filter WinEventLog:Security by Account Name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25309#M4088</link>
      <description>&lt;P&gt;Just as an FYI, I noticed a typo in this.  Transforms.conf now reads as below.  This did not fix the issue however.&lt;/P&gt;

&lt;P&gt;[wminull]&lt;BR /&gt;
REGEX = (?msi)^Account_Name=splunkrdba&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullqueue&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25309#M4088</guid>
      <dc:creator>jturnerrdba</dc:creator>
      <dc:date>2020-09-28T13:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: filter WinEventLog:Security by Account Name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25310#M4089</link>
      <description>&lt;P&gt;I've finally gotten this to work on my own.&lt;/P&gt;

&lt;P&gt;A few things changed.  &lt;/P&gt;

&lt;P&gt;1) I upgraded to the newest version of Splunk&lt;BR /&gt;
2) I changed the regex statement to be just regex = splunkrdba&lt;BR /&gt;
3) I change transforms.conf to be FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;I believe the 1st didn't really do much, but I wanted to mention it.  I think the second one finally caught what I wanted without catching anything else, and I believe the capital Q is necessary.  Hope this helps someone else.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2013 18:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-WinEventLog-Security-by-Account-Name/m-p/25310#M4089</guid>
      <dc:creator>jturnerrdba</dc:creator>
      <dc:date>2013-02-11T18:23:19Z</dc:date>
    </item>
  </channel>
</rss>

