<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to whitelist only Error EventID's sent from UF to Indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518377#M87647</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;From Windows Event Viewer logs we can onboard all Event ID's generated for "Application" and "System" Event logs but unable to onboard filtered events based on Event Code OR Type(Error/Warning).&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below is inputs.conf written by me to filter-out the events which is not working.Also followed the below splunk docs.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;[WinEventLog ://Application]&lt;DIV&gt;disabled = 0&lt;/DIV&gt;&lt;DIV&gt;whitelist = Type="^[Error|Critical]"&lt;/DIV&gt;&lt;DIV&gt;index = test&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;OR&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[WinEventLog://Application]&lt;/SPAN&gt;&lt;DIV&gt;disabled = 0&lt;/DIV&gt;&lt;DIV&gt;whitelist = EventCode="1001|11707"&lt;/DIV&gt;&lt;DIV&gt;index = test&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[WinEventLog://System]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;disabled = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whitelist 1 = Event Code=7011&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whitelist 2 = Type="^[Error|Critical]"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;index = test&lt;/SPAN&gt;&lt;BR /&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-Event-Log-for-Critical-Error/td-p/502991" target="_blank" rel="noopener noreferrer"&gt;https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-Event-Log-for-Critical-Error/td-p/502991&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/MonitorWindowseventlogdata" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;Please check with your seniors on How can we whitelist only Error events in Application or System Event logs. Please find the attachement&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sneha_nv_0-1599544724108.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10701iB52D160997B1D2F1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sneha_nv_0-1599544724108.png" alt="sneha_nv_0-1599544724108.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 08 Sep 2020 07:33:12 GMT</pubDate>
    <dc:creator>sneha_nv</dc:creator>
    <dc:date>2020-09-08T07:33:12Z</dc:date>
    <item>
      <title>Unable to whitelist only Error EventID's sent from UF to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518377#M87647</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;From Windows Event Viewer logs we can onboard all Event ID's generated for "Application" and "System" Event logs but unable to onboard filtered events based on Event Code OR Type(Error/Warning).&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below is inputs.conf written by me to filter-out the events which is not working.Also followed the below splunk docs.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;[WinEventLog ://Application]&lt;DIV&gt;disabled = 0&lt;/DIV&gt;&lt;DIV&gt;whitelist = Type="^[Error|Critical]"&lt;/DIV&gt;&lt;DIV&gt;index = test&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;OR&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[WinEventLog://Application]&lt;/SPAN&gt;&lt;DIV&gt;disabled = 0&lt;/DIV&gt;&lt;DIV&gt;whitelist = EventCode="1001|11707"&lt;/DIV&gt;&lt;DIV&gt;index = test&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[WinEventLog://System]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;disabled = 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whitelist 1 = Event Code=7011&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whitelist 2 = Type="^[Error|Critical]"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;index = test&lt;/SPAN&gt;&lt;BR /&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-Event-Log-for-Critical-Error/td-p/502991" target="_blank" rel="noopener noreferrer"&gt;https://community.splunk.com/t5/Getting-Data-In/Monitor-Windows-Event-Log-for-Critical-Error/td-p/502991&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/MonitorWindowseventlogdata" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.0.2006/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;Please check with your seniors on How can we whitelist only Error events in Application or System Event logs. Please find the attachement&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sneha_nv_0-1599544724108.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10701iB52D160997B1D2F1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sneha_nv_0-1599544724108.png" alt="sneha_nv_0-1599544724108.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 08 Sep 2020 07:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518377#M87647</guid>
      <dc:creator>sneha_nv</dc:creator>
      <dc:date>2020-09-08T07:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to whitelist only Error EventID's sent from UF to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518417#M87649</link>
      <description>&lt;P&gt;try below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://Application]
disabled = 0
whitelist = EventCode="^(1001|11707)$"
index = test&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://System]
disabled = 0
whitelist1 = EventCode="7011" #no space between whitelist and number
whitelist2 = Type="^(Error|Critical)$"
index = test&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Sep 2020 11:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518417#M87649</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-08T11:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to whitelist only Error EventID's sent from UF to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518418#M87650</link>
      <description>&lt;P&gt;Also If I don't know the error Eventcode and only based on Type(Error/Warning) want to collect the "Application" and "Sysytem" logs&lt;BR /&gt;&lt;BR /&gt;What will be my inputs.conf in this scenario while on-boarding data from UF to Indexer&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 11:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/518418#M87650</guid>
      <dc:creator>sneha_nv</dc:creator>
      <dc:date>2020-09-08T11:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to whitelist only Error EventID's sent from UF to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/519344#M87825</link>
      <description>&lt;P&gt;it worked for me&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[WinEventLog://System]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;disabled = 0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;whitelist1 = Type="^[Error]"&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;whitelist2 = Type="^[Critical]"&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;whitelist3 = Type="^[Warning]"&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;index = test&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[WinEventLog://Application]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;disabled = 0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;whitelist1 = Type="^[Error]"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;whitelist2 = Type="^[Critical]"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;whitelist3 = Type="^[Warning]"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;index = test&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 06:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/519344#M87825</guid>
      <dc:creator>sneha_nv</dc:creator>
      <dc:date>2020-09-14T06:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to whitelist only Error EventID's sent from UF to Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/519348#M87826</link>
      <description>&lt;P&gt;I suggest you to replace [] with (), characters between [] will match individually for example&lt;/P&gt;&lt;P&gt;[Error] - matches E or r or r or o or r anywhere in the event.&lt;/P&gt;&lt;P&gt;(Error) -matches only Error&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 07:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-whitelist-only-Error-EventID-s-sent-from-UF-to-Indexer/m-p/519348#M87826</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-14T07:17:28Z</dc:date>
    </item>
  </channel>
</rss>

