<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I edit my wineventlog configuration to blacklist a specific SourceName? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223763#M43809</link>
    <description>&lt;P&gt;I'm glad it worked out. Remember its key=regex when you black/whitelist.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2016 13:03:01 GMT</pubDate>
    <dc:creator>alemarzu</dc:creator>
    <dc:date>2016-01-13T13:03:01Z</dc:date>
    <item>
      <title>How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223760#M43806</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;

&lt;P&gt;I am having trouble finding a solution to blacklisting a SourceName called "SCLIntra Mobile Sync Service" on my forwarders.  Anyone?&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Application]
checkpointInterval = 5
current_only = 0
disabled = 0
start_from = oldest
blacklist = SourceName="SCLIntra Mobile Sync Service"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
James&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 18:44:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223760#M43806</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-12T18:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223761#M43807</link>
      <description>&lt;P&gt;Rmsit,&lt;/P&gt;

&lt;P&gt;Try this;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;blacklist = SourceName=\"SCLIntra\sMobile\sSync\sService\"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Jan 2016 19:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223761#M43807</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-01-12T19:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223762#M43808</link>
      <description>&lt;P&gt;This works!  Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2016 23:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223762#M43808</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-12T23:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223763#M43809</link>
      <description>&lt;P&gt;I'm glad it worked out. Remember its key=regex when you black/whitelist.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 13:03:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223763#M43809</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-01-13T13:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223764#M43810</link>
      <description>&lt;P&gt;Spoke too soon...still not working.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 19:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223764#M43810</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-13T19:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223765#M43811</link>
      <description>&lt;P&gt;This is working on my events with Splunk 6.3.x, was't working till I've found a "." at the end of the string.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;blacklist = SourceName="SCLIntra Mobile Sync Service\."
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 13 Jan 2016 21:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223765#M43811</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-01-13T21:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223766#M43812</link>
      <description>&lt;P&gt;Thank you.  I will try it.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 21:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223766#M43812</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-13T21:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223767#M43813</link>
      <description>&lt;P&gt;I am still seeing this SoureName from my forwarder.  Is it possible the UF cannot filter it?  The UF is version 6.3.1.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 13:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223767#M43813</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-14T13:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223768#M43814</link>
      <description>&lt;P&gt;Universal Forwarders can filter wineventlogs since Splunk 6+.&lt;/P&gt;

&lt;P&gt;Can you paste an event sample ?  Are u black/whitelisting any other thing ?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 14:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223768#M43814</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-01-14T14:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223769#M43815</link>
      <description>&lt;P&gt;It is normal Windows event log data.  Nothing else is blacklisted/whitelisted for the Application log.&lt;/P&gt;

&lt;P&gt;1/14/16&lt;BR /&gt;
9:56:32.000 AM  &lt;/P&gt;

&lt;P&gt;01/14/2016 09:56:32 AM&lt;BR /&gt;
LogName=Application&lt;BR /&gt;
SourceName=SCLIntra Mobile Sync Service&lt;BR /&gt;
EventCode=100&lt;BR /&gt;
EventType=2&lt;BR /&gt;
Severity = Error&lt;BR /&gt;&lt;BR /&gt;
 SourceName = SCLIntra Mobile Sync Service&lt;BR /&gt;&lt;BR /&gt;
 host = v1651ancay014&lt;BR /&gt;&lt;BR /&gt;
 index = wineventlog&lt;BR /&gt;&lt;BR /&gt;
 linecount = 55&lt;BR /&gt;&lt;BR /&gt;
 source = WinEventLog:Application&lt;BR /&gt;&lt;BR /&gt;
 sourcetype = WinEventLog:Application&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 15:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223769#M43815</guid>
      <dc:creator>rmsit</dc:creator>
      <dc:date>2016-01-14T15:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my wineventlog configuration to blacklist a specific SourceName?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223770#M43816</link>
      <description>&lt;P&gt;Its weird, try this, tested on Application logs this time.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;blacklist = SourceName=%^SLCIntra\sMobile\ssSync\ssService$%
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;EDIT: Had a typo on SLCIntra.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 17:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-wineventlog-configuration-to-blacklist-a/m-p/223770#M43816</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-01-14T17:47:48Z</dc:date>
    </item>
  </channel>
</rss>

