<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reduce the noise out of Security EventCodes.. in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666006#M11763</link>
    <description>&lt;P&gt;That's not really a Splunk or ES-related question. It's related to your data and your use-cases. If you filter out some data, you don't have it. And if you don't have events, you can't base your searches (and thus use-cases) on them. As simple as that.&lt;/P&gt;&lt;P&gt;It's more a windows-related question to your admins to help you review the use cases you want to enable.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 14:10:33 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-10-24T14:10:33Z</dc:date>
    <item>
      <title>Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665875#M11760</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I'm trying to reduce the noise out of these EventCodes which we can exclude in the enterprise security point of view.&lt;BR /&gt;Below are my stats of EventCodes, Could any one pls guide me in this&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;EventCode count&lt;BR /&gt;4624 25714108&lt;BR /&gt;4799 12271228&lt;BR /&gt;5140 4180598&lt;BR /&gt;4672 2896823&lt;BR /&gt;4769 2871064&lt;BR /&gt;4776 2177516&lt;BR /&gt;4798 1771003&lt;BR /&gt;4768 1149826&lt;BR /&gt;4662 919694&lt;BR /&gt;4793 667396&lt;BR /&gt;4627 428382&lt;BR /&gt;4771 344400&lt;BR /&gt;4702 261942&lt;BR /&gt;4625 229393&lt;BR /&gt;4698 131404&lt;BR /&gt;4699 107254&lt;BR /&gt;5059 92679&lt;BR /&gt;4611 86837&lt;BR /&gt;5379 74950&lt;BR /&gt;4735 55988&lt;BR /&gt;4770 31850&lt;BR /&gt;4946 31586&lt;BR /&gt;4719 30067&lt;BR /&gt;4688 27561&lt;BR /&gt;4948 26952&lt;BR /&gt;4945 19959&lt;BR /&gt;4648 17191&lt;BR /&gt;4825 17016&lt;BR /&gt;4697 13155&lt;BR /&gt;6416 6977&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 15:47:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665875#M11760</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-10-23T15:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665896#M11761</link>
      <description>&lt;P&gt;Please give us your definition of "noise".&lt;/P&gt;&lt;P&gt;Do none of your other questions on the same topic address this, too?&lt;/P&gt;&lt;P&gt;Have you considered using Ingest Actions to avoid indexing unwanted data?&amp;nbsp; See &lt;A href="https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Using_ingest_actions_in_Splunk_Enterprise" target="_blank"&gt;https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Using_ingest_actions_in_Splunk_Enterprise &lt;/A&gt;and &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Data/DataIngest" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Data/DataIngest&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 16:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665896#M11761</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-23T16:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665925#M11762</link>
      <description>&lt;P&gt;There are a number of event codes that have static descriptions of the event in each iteration of the event. This page shows how to trim off the event descriptions on ingest. This can save a lot of data.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/Configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/Configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 21:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/665925#M11762</guid>
      <dc:creator>fredclown</dc:creator>
      <dc:date>2023-10-23T21:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666006#M11763</link>
      <description>&lt;P&gt;That's not really a Splunk or ES-related question. It's related to your data and your use-cases. If you filter out some data, you don't have it. And if you don't have events, you can't base your searches (and thus use-cases) on them. As simple as that.&lt;/P&gt;&lt;P&gt;It's more a windows-related question to your admins to help you review the use cases you want to enable.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 14:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666006#M11763</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-24T14:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666113#M11764</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/146503"&gt;@fredclown&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It will be there by default, no need of defining again !&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 09:59:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666113#M11764</guid>
      <dc:creator>AL3Z</dc:creator>
      <dc:date>2023-10-25T09:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reduce the noise out of Security EventCodes..</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666193#M11768</link>
      <description>&lt;P&gt;The event code description trimming is not turned on by default. You need to specifically turn it on in a local props.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 16:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Reduce-the-noise-out-of-Security-EventCodes/m-p/666193#M11768</guid>
      <dc:creator>fredclown</dc:creator>
      <dc:date>2023-10-25T16:05:19Z</dc:date>
    </item>
  </channel>
</rss>

