<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whitelist Services? How in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Services-How/m-p/313011#M58649</link>
    <description>&lt;P&gt;You can find how to monitor WinHostMon at &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowshostinformation"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowshostinformation&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;See type attribute to set which service to monitor.&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Queries computer information.
[WinHostMon://computer]
type = Computer
interval = 300

# Queries OS information. 
# 'interval' set to a negative number tells Splunk Enterprise to
# run the input once only. 
[WinHostMon://os]
type = operatingSystem
interval = -1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For WMI please check &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorWindowseventlogdata"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorWindowseventlogdata&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Example: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WMI:AppAndSys]
server = foo, bar
interval = 10
event_log_file = Application, System, Directory Service
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 28 Nov 2017 11:36:54 GMT</pubDate>
    <dc:creator>damien_chillet</dc:creator>
    <dc:date>2017-11-28T11:36:54Z</dc:date>
    <item>
      <title>Whitelist Services? How</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Services-How/m-p/313010#M58648</link>
      <description>&lt;P&gt;How do you whitelist services you wish to monitor and not forward redundant ones to the Splunk Server....&lt;/P&gt;

&lt;P&gt;I've done before on WinEventLog but however not sure how to use WinHostMon or WMI to whitelist, will apperciate if someone has working configuration that whitelist/blacklist services&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 06:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Services-How/m-p/313010#M58648</guid>
      <dc:creator>Kitteh</dc:creator>
      <dc:date>2017-11-28T06:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelist Services? How</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Services-How/m-p/313011#M58649</link>
      <description>&lt;P&gt;You can find how to monitor WinHostMon at &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowshostinformation"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowshostinformation&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;See type attribute to set which service to monitor.&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Queries computer information.
[WinHostMon://computer]
type = Computer
interval = 300

# Queries OS information. 
# 'interval' set to a negative number tells Splunk Enterprise to
# run the input once only. 
[WinHostMon://os]
type = operatingSystem
interval = -1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For WMI please check &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorWindowseventlogdata"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/MonitorWindowseventlogdata&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Example: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WMI:AppAndSys]
server = foo, bar
interval = 10
event_log_file = Application, System, Directory Service
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Nov 2017 11:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Whitelist-Services-How/m-p/313011#M58649</guid>
      <dc:creator>damien_chillet</dc:creator>
      <dc:date>2017-11-28T11:36:54Z</dc:date>
    </item>
  </channel>
</rss>

