<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to select only &amp;quot;Security logs&amp;quot; from  Windows? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320644#M59829</link>
    <description>&lt;P&gt;This worked! thank you very much!&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2018 22:51:35 GMT</pubDate>
    <dc:creator>mmcarty</dc:creator>
    <dc:date>2018-03-06T22:51:35Z</dc:date>
    <item>
      <title>How to select only "Security logs" from  Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320642#M59827</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I installed a Universal Forwarder(UF) in a Windows servers box, I didn't select the customize options, I only did next and only specified my deployer, now after I am done, I would like to tell the windows servers that I only need Windows Security Logs (from the event viewer) to be forwarded to my Splunk instance, how do i do that? how do I change that?&lt;/P&gt;

&lt;P&gt;Thank you! &lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320642#M59827</guid>
      <dc:creator>mmcarty</dc:creator>
      <dc:date>2018-03-06T19:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to select only "Security logs" from  Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320643#M59828</link>
      <description>&lt;P&gt;Look for inputs.conf in your Universal Forwarder. ($SPLUNK_HOME/etc/apps, should be under some app). The inputs.conf file (there can be many, find one which has &lt;CODE&gt;[WinEventLog:....&lt;/CODE&gt; type stanza). You can say &lt;CODE&gt;disabled = 1&lt;/CODE&gt; for all entries which you want to disable. Just keep &lt;CODE&gt;disabled =0&lt;/CODE&gt; for &lt;CODE&gt;[WinEventLog:Security]&lt;/CODE&gt; stanza.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 20:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320643#M59828</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-03-06T20:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to select only "Security logs" from  Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320644#M59829</link>
      <description>&lt;P&gt;This worked! thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 22:51:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-select-only-quot-Security-logs-quot-from-Windows/m-p/320644#M59829</guid>
      <dc:creator>mmcarty</dc:creator>
      <dc:date>2018-03-06T22:51:35Z</dc:date>
    </item>
  </channel>
</rss>

