<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Include only certain codes. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417466#M6416</link>
    <description>&lt;P&gt;Hi Vijeta,&lt;/P&gt;

&lt;P&gt;Yes! Thank you very much. Worked like a charm.&lt;/P&gt;

&lt;P&gt;Bogdan.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2019 12:33:33 GMT</pubDate>
    <dc:creator>bogdan_nicolesc</dc:creator>
    <dc:date>2019-01-23T12:33:33Z</dc:date>
    <item>
      <title>Include only certain codes.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417464#M6414</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I have a search like this:&lt;/P&gt;

&lt;P&gt;(index=* OR index=_&lt;EM&gt;) (source="WMI:WinEventLog:Security" OR source="WinEventLog:Security")  Type=&lt;/EM&gt; NOT (EventCode=4719 OR EventCode=4624 OR EventCode=4672 OR EventCode=4627 OR EventCode=4634 OR EventCode=4648 OR EventCode=4688 OR EventCode=4616 OR EventCode=4826 OR EventCode=4957 OR EventCode=4776 OR EventCode=1100 OR EventCode=4902 OR EventCode=4647 OR EventCode=1101 OR EventCode=4696 OR EventCode=4905 OR EventCode=4904)   | eval EventCode=if(EventCode="4801","Deblocat4801",EventCode)   | eval EventCode=if(EventCode="4800","Blocat4800",EventCode)   | eval EventCode=if(EventCode="4625","ParolaGresita4625",EventCode)  | eval Security_ID=if(Security_ID="HUB\Bogdan.NICOLESCU","Bogdan.Nicolescu",Security_ID)  | eval Security_ID=if(Security_ID="S-1-5-21-2194086089-2732682161-3381787425-7759","Bogdan.Nicolescu.7759",Security_ID)  | eval Security_ID=if(Security_ID="HUB\bogdan.nicolescu","Bogdan.Nicolescu.2",Security_ID)   | rename EventCode AS RootObject.EventCode Security_ID AS RootObject.Security_ID | fields "_time" "host" "source" "sourcetype" "RootObject.EventCode" "RootObject.Security_ID" | bucket _time  span=1s | stats dedup_splitvals=t dc(RootObject.EventCode) AS "Distinct Count of EventCode"  by _time, RootObject.EventCode, RootObject.Security_ID | sort limit=100000 _time | rename RootObject.EventCode AS EventCode RootObject.Security_ID AS Security_ID  | fillnull "Distinct Count of EventCode" | fields _time, EventCode, Security_ID, "Distinct Count of EventCode"&lt;/P&gt;

&lt;P&gt;My question is, how can i include in search only:&lt;/P&gt;

&lt;P&gt;Security_ID="Bogdan.Nicolescu" Security_ID="Bogdan.Nicolescu.2"  Security_ID="Bogdan.Nicolescu.7759"&lt;/P&gt;

&lt;P&gt;So i can get rid of exludes of:&lt;/P&gt;

&lt;P&gt;NOT (EventCode=4719 OR EventCode=4624 OR EventCode=4672 OR EventCode=4627 OR EventCode=4634 OR EventCode=4648 OR EventCode=4688 OR EventCode=4616 OR EventCode=4826 OR EventCode=4957 OR EventCode=4776 OR EventCode=1100 OR EventCode=4902 OR EventCode=4647 OR EventCode=1101 OR EventCode=4696 OR EventCode=4905 OR EventCode=4904)&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417464#M6414</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2020-09-29T22:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Include only certain codes.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417465#M6415</link>
      <description>&lt;P&gt;You can write your main search as &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index= OR index=_) (source="WMI:WinEventLog:Security" OR source="WinEventLog:Security") Type=* (Security_ID="HUB\bogdan.nicolescu" OR Security_ID="HUB\bogdan.nicolescu" OR Security_ID="S-1-5-21-2194086089-2732682161-3381787425-7759")| eval Security_ID=if(Security_ID="S-1-5-21-2194086089-2732682161-3381787425-7759","Bogdan.Nicolescu.7759",Security_ID) | eval Security_ID=if(Security_ID="HUB\bogdan.nicolescu","Bogdan.Nicolescu.2",Security_ID) | rename EventCode AS RootObject.EventCode Security_ID AS RootObject.Security_ID | fields "_time" "host" "source" "sourcetype" "RootObject.EventCode" "RootObject.Security_ID" | bucket _time span=1s | stats dedup_splitvals=t dc(RootObject.EventCode) AS "Distinct Count of EventCode" by _time, RootObject.EventCode, RootObject.Security_ID | sort limit=100000 _time | rename RootObject.EventCode AS EventCode RootObject.Security_ID AS Security_ID | fillnull "Distinct Count of EventCode" | fields _time, EventCode, Security_ID, "Distinct Count of EventCode"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 22 Jan 2019 17:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417465#M6415</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-01-22T17:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Include only certain codes.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417466#M6416</link>
      <description>&lt;P&gt;Hi Vijeta,&lt;/P&gt;

&lt;P&gt;Yes! Thank you very much. Worked like a charm.&lt;/P&gt;

&lt;P&gt;Bogdan.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 12:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Include-only-certain-codes/m-p/417466#M6416</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2019-01-23T12:33:33Z</dc:date>
    </item>
  </channel>
</rss>

