<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklist windows event log by Host Application field in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509162#M86601</link>
    <description>&lt;P&gt;*Updated* Have a try with this blacklist stanza:&lt;/P&gt;&lt;P&gt;blacklist1 = EventCode="4103" Message="Host Application\s=\s*.*SolarWinds\.APM\.Probes"&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jul 2020 06:15:21 GMT</pubDate>
    <dc:creator>anmolpatel</dc:creator>
    <dc:date>2020-07-15T06:15:21Z</dc:date>
    <item>
      <title>Blacklist windows event log by Host Application field</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509157#M86600</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I would like to exclude the following windows event log on the universal forwarder.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;07/15/2020 08:38:55 AM
LogName=Microsoft-Windows-PowerShell/Operational
SourceName=Microsoft-Windows-PowerShell
EventCode=4103
EventType=4
Type=Information
ComputerName=HA-AGM-DB-01.SSI.LOCAL
User=NOT_TRANSLATED
Sid=S-1-5-21-2993187273-2588912068-3154952105-14529
SidType=0
TaskCategory=Executing Pipeline
OpCode=To be used when operation is just executing a method
RecordNumber=90748
Keywords=None
Message=CommandInvocation(Out-Host): "Out-Host"
CommandInvocation(Out-Default): "Out-Default"
ParameterBinding(Out-Default): name="Transcript"; value="True"


Context:
        Severity = Informational
        Host Name = ApmPSHost
        Host Version = 1.0
        Host ID = 85e424db-4fce-46cb-90d4-bace72bb3e2a
        Host Application = SWJobEngineWorker2.exe 3e167b33-0a26-4f7e-9964-e38b1e939cc6 6612 AgentPlugin SolarWinds.APM.Probes
        Engine Version = 5.1.14393.3383
        Runspace ID = 3c6aab92-96b5-464d-8659-0e81de6d4ec9
        Pipeline ID = 1
        Command Name = 
        Command Type = Script
        Script Name = 
        Command Path = 
        Sequence Number = 193
        User = xxxxx
        Connected User = 
        Shell ID = Microsoft.PowerShell


User Data:&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried with this blacklist :&lt;/P&gt;&lt;P&gt;blacklist = EventCode="4103" Message="Host\sApplication\s=*SolarWinds.APM.Probes"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 02:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509157#M86600</guid>
      <dc:creator>thund_ssi</dc:creator>
      <dc:date>2020-07-15T02:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist windows event log by Host Application field</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509162#M86601</link>
      <description>&lt;P&gt;*Updated* Have a try with this blacklist stanza:&lt;/P&gt;&lt;P&gt;blacklist1 = EventCode="4103" Message="Host Application\s=\s*.*SolarWinds\.APM\.Probes"&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 06:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509162#M86601</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-07-15T06:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist windows event log by Host Application field</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509163#M86602</link>
      <description>&lt;P&gt;Thanks, but not working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 03:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509163#M86602</guid>
      <dc:creator>thund_ssi</dc:creator>
      <dc:date>2020-07-15T03:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist windows event log by Host Application field</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509174#M86604</link>
      <description>&lt;P&gt;I got it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist1 = EventCode="4103" Message="Host Application =\s+.*SolarWinds.APM.Probes"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 15 Jul 2020 06:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Blacklist-windows-event-log-by-Host-Application-field/m-p/509174#M86604</guid>
      <dc:creator>thund_ssi</dc:creator>
      <dc:date>2020-07-15T06:09:50Z</dc:date>
    </item>
  </channel>
</rss>

