<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows - Filtering Forwarded Events based on LogName in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553791#M91809</link>
    <description>&lt;P&gt;Well, that's the regex format I'm using &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for confirming it should work. I'll test it before rolling out to prod anyway so I don't assume that something works and suddenly get surprised that it doesn't &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 16:40:56 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-06-02T16:40:56Z</dc:date>
    <item>
      <title>Windows - Filtering Forwarded Events based on LogName</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553711#M91798</link>
      <description>&lt;P&gt;I have a use-case:&lt;/P&gt;&lt;P&gt;There is a WEC server receving logs from a server farm. I need to forward only security events from Forwarded Events Log. Judging from inputs.conf specs it should be enough to define an input such as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[WinEventLog://ForwardedEvents]
current_only = 0
disabled = 0
index = whatever
renderXml = true
whitelist = LogName=Security&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this configuration should provide me with only security events forwarded from the source hosts being pulled by UF, right? The rest of Forwarder Events log should be left alone?&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 13:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553711#M91798</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-05-31T13:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Windows - Filtering Forwarded Events based on LogName</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553751#M91803</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The config should work, if not see the regex format as described here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/admin/Inputsconf#Event_Log_allow_list_and_deny_list_formats" target="_blank"&gt;inputs.conf - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 02:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553751#M91803</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-01T02:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Windows - Filtering Forwarded Events based on LogName</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553753#M91805</link>
      <description>&lt;P&gt;I mean it only filters the Security events as you required. Docs says,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# Filtering at the input layer is desirable to reduce the total
# processing load in network transfer and computation on the Splunk platform
# nodes that acquire and processing Event Log data.

whitelist = &amp;lt;list of eventIDs&amp;gt; | key=regex [key=regex]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 02:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553753#M91805</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-01T02:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Windows - Filtering Forwarded Events based on LogName</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553791#M91809</link>
      <description>&lt;P&gt;Well, that's the regex format I'm using &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for confirming it should work. I'll test it before rolling out to prod anyway so I don't assume that something works and suddenly get surprised that it doesn't &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553791#M91809</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-06-02T16:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Windows - Filtering Forwarded Events based on LogName</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/554128#M91839</link>
      <description>&lt;P&gt;It seems that the syntax was almost OK.&lt;/P&gt;&lt;P&gt;The regex should be delimited, otherwise the UF throws an error into logs at startup and ignores the condition.&lt;/P&gt;&lt;P&gt;So it should say:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;whitelist = LogName="Security"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 02 Jun 2021 16:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/554128#M91839</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-06-02T16:40:05Z</dc:date>
    </item>
  </channel>
</rss>

