<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help filter out unwanted data from indexing using nullqueue Please in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539718#M90403</link>
    <description>&lt;P&gt;blacklist5 = $XmlRegex="NT AUTHORITY\\SYSTEM"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used this in the end as i really wasnt bothered what event id it came from im not intrested in events from that particular system account. Seems to be working and yes you are right i just learned today that you have to escape any \ and put \\ for the regex to handle it.&lt;/P&gt;&lt;P&gt;thanks again for your time its very much appreciated.&lt;/P&gt;&lt;P&gt;Cuppa coffee to you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Feb 2021 15:22:57 GMT</pubDate>
    <dc:creator>marcusmartin</dc:creator>
    <dc:date>2021-02-12T15:22:57Z</dc:date>
    <item>
      <title>Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539651#M90391</link>
      <description>&lt;P&gt;Hi if someone could please help that would be great, I have events showing up in the indexer that are pushing me over my license, alot of it is useless to me information and i have been trying to wrap my head around filtering it out using regex but i just cant get my head around it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is a typical event i would like to rid my indexer of, i cant just block all the events with 4634&amp;nbsp; as some of them are valid, but i would like to block all events where the "Targetusersid" is similar to DOMAIN\ABC-12345$&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Event&lt;/SPAN&gt; &lt;SPAN class="t"&gt;xmlns=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;A href="http://schemas.microsoft.com/win/2004/08/events/event" target="_blank" rel="noopener"&gt;http://schemas.microsoft.com/win/2004/08/events/event&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;System&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Provider&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Microsoft-Windows-Security-Auditing&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Guid=&lt;/SPAN&gt;&lt;SPAN&gt;'{&lt;/SPAN&gt;&lt;SPAN class="t"&gt;54849625-5478-4994-A5BA-3E3B0328C30D&lt;/SPAN&gt;&lt;SPAN&gt;}'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;EventID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;4634&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/EventID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Version&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Version&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Level&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Level&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Task&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12545&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Task&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Opcode&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Opcode&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Keywords&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0x8020000000000000&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Keywords&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TimeCreated&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SystemTime=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021-02-12T08:24:29.977950700Z&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;EventRecordID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;314243098&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/EventRecordID&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Correlation/&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Execution&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ProcessID=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;852&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ThreadID=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12388&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Channel&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Security&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Channel&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Computer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;domaincontoller.domainname&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Computer&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Security/&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/System&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;EventData&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetUserSid&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;DomainName\machine-name$&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetUserName&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;Machine-Name&lt;/SPAN&gt;&lt;SPAN class="t"&gt;$&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetDomainName&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;DomainName&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;TargetLogonId&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0x22b9251d&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;LogonType&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/EventData&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/Event&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Props.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;[XmlWinEventLog:Security]&lt;BR /&gt;TRANSFORMS-xml = xmlnull&lt;BR /&gt;REGEX=(?m)^EventCode="(4662|566)" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;REGEX=(?m)^EventCode="(4656|4670|4663|4703|4658|4688)" Message="Account Name:(\W+\w+$)"&lt;BR /&gt;REGEX=(?m)^EventCode="(4688|4689)" Message="%SplunkUniversalForwarder%"&lt;BR /&gt;REGEX=(?m)^EventCode="6278" Message="Network Policy Server granted full access to a user because the host met the defined health policy."&lt;BR /&gt;REGEX=(?m)^EventCode="(4624|4634|4627|4648)" Message="Account\sName:.*[\S\s]*Account\sName:\s+[\S+]+[\$]"&lt;/P&gt;&lt;P&gt;Transforms.conf&lt;/P&gt;&lt;P&gt;[xmlnull]&lt;BR /&gt;REGEX= NO idea &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 09:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539651#M90391</guid>
      <dc:creator>marcusmartin</dc:creator>
      <dc:date>2021-02-12T09:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539657#M90392</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/2436"&gt;@marcusmartin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since you are using XML format you can filter events using $XmlRegex directive. There is no need to use nullQueue. Also the REGEX settings in props does not work, you should put them into inputs.conf on universal forwarder changing to XML format.&lt;/P&gt;&lt;P&gt;You can use below for filtering&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;inputs.conf

[WinEventLog://Security]
blacklist2 = $XmlRegex="&amp;lt;EventID&amp;gt;4634&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data Name='TargetUserSid'&amp;gt;[^\\]+\\[^&amp;lt;]+\$"&lt;/LI-CODE&gt;&lt;P&gt;Please try below;&lt;/P&gt;&lt;P&gt;Please also look at below document for filtering unnecessary data from Windows logs. You can use this filters also.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/8.1.1/User/Configuration#Configure_event_cleanup_best_practices_in_props.conf" target="_blank"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/8.1.1/User/Configuration#Configure_event_cleanup_best_practices_in_props.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 09:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539657#M90392</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-12T09:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539667#M90394</link>
      <description>&lt;P&gt;Perfect response, thankyou so much i would never have figured it out im sure. much respect.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 10:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539667#M90394</guid>
      <dc:creator>marcusmartin</dc:creator>
      <dc:date>2021-02-12T10:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539672#M90397</link>
      <description>&lt;P class="lia-align-justify"&gt;Could I be a real pain How would you block&amp;nbsp;&lt;SPAN class="t"&gt;TargetUserSid&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NT&lt;/SPAN&gt; &lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;AUTHORITY&lt;/SPAN&gt;\&lt;SPAN class="t"&gt;SYSTEM using regex?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 12:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539672#M90397</guid>
      <dc:creator>marcusmartin</dc:creator>
      <dc:date>2021-02-12T12:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539673#M90398</link>
      <description>&lt;P&gt;blacklist2 = $XmlRegex="&amp;lt;EventID&amp;gt;4634&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data Name='TargetUserSid'&amp;gt;NT AUTHORITY\SYSTEM"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just tried this but im thick when it comes to regex&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 12:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539673#M90398</guid>
      <dc:creator>marcusmartin</dc:creator>
      <dc:date>2021-02-12T12:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539690#M90401</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/2436"&gt;@marcusmartin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can try below; (You should escape "\")&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blacklist2 = $XmlRegex="&amp;lt;EventID&amp;gt;4634&amp;lt;\/EventID&amp;gt;.*&amp;lt;Data Name='TargetUserSid'&amp;gt;NT AUTHORITY\\SYSTEM"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 13:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539690#M90401</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-12T13:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help filter out unwanted data from indexing using nullqueue Please</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539718#M90403</link>
      <description>&lt;P&gt;blacklist5 = $XmlRegex="NT AUTHORITY\\SYSTEM"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used this in the end as i really wasnt bothered what event id it came from im not intrested in events from that particular system account. Seems to be working and yes you are right i just learned today that you have to escape any \ and put \\ for the regex to handle it.&lt;/P&gt;&lt;P&gt;thanks again for your time its very much appreciated.&lt;/P&gt;&lt;P&gt;Cuppa coffee to you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 15:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-filter-out-unwanted-data-from-indexing-using-nullqueue/m-p/539718#M90403</guid>
      <dc:creator>marcusmartin</dc:creator>
      <dc:date>2021-02-12T15:22:57Z</dc:date>
    </item>
  </channel>
</rss>

