<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trimming Event Logs from a Domain Controller in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46902#M8871</link>
    <description>&lt;P&gt;The technical answer is that you can filter using regular expressions. Examples are in the documentation on page &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Routeandfilterdatad"&gt;Route and Filter data&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In practise in your scenario I'd configure multiple filters with the different types of data you are interested in.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2012 09:27:29 GMT</pubDate>
    <dc:creator>dart</dc:creator>
    <dc:date>2012-09-05T09:27:29Z</dc:date>
    <item>
      <title>Trimming Event Logs from a Domain Controller</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46901#M8870</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I need some help in managing some logging to my Splunk server.  We have an enterprise-wide set of Domain Controllers.  Using this is a particular network segment that I need to monitor.  I need to monitor the System &amp;amp; Security event log on the DC, but I need to trim the events so that the Splunk Aggregator only gets events from this subset (devices, users in specific OU/subnets).  The enterprise wide logs would absolute pummel my Splunk instance.&lt;/P&gt;

&lt;P&gt;What is the best way to trim the event log?  I know that this is probably an incomplete question so I may need some guidance on what other information would help.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2012 18:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46901#M8870</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2012-08-29T18:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trimming Event Logs from a Domain Controller</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46902#M8871</link>
      <description>&lt;P&gt;The technical answer is that you can filter using regular expressions. Examples are in the documentation on page &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Routeandfilterdatad"&gt;Route and Filter data&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In practise in your scenario I'd configure multiple filters with the different types of data you are interested in.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 09:27:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46902#M8871</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-09-05T09:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trimming Event Logs from a Domain Controller</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46903#M8872</link>
      <description>&lt;P&gt;Thanks for your suggestions.  I will look into that.  I have used transforms/props to filter out certain data but that was usually looking for a specific event code.  In this I want everything that has to do with either users or computers in a specific OU tree subset of the whole domain....&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2012 17:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trimming-Event-Logs-from-a-Domain-Controller/m-p/46903#M8872</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2012-09-11T17:11:40Z</dc:date>
    </item>
  </channel>
</rss>

