<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: blacklist regex help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654551#M226140</link>
    <description>&lt;P&gt;What have you tried so far?&amp;nbsp; Is the sAMAccuontName field already properly extracted (the complete value is present)?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2023 20:04:22 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-08-16T20:04:22Z</dc:date>
    <item>
      <title>blacklist regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654509#M226134</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am trying to blacklist an event that is tied to a specific sAMAccountName which is&amp;nbsp;sAMAccountName="Alertz - ProductFeedback" .&amp;nbsp; The only way I can think to achieve this is maybe with a blacklist regex statement but I am not sure and not very good with regex. Below is a sample event. Please let me know if there are any questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;08/16/2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;09:34:07.541&lt;/SPAN&gt; &lt;SPAN class=""&gt;dcName=RNBSAD1.rightnetworks.com&lt;/SPAN&gt; &lt;SPAN class=""&gt;admonEventType=Update&lt;/SPAN&gt; &lt;SPAN class=""&gt;Names:&lt;/SPAN&gt; &lt;SPAN class=""&gt;objectCategory=CN=Group&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;CN=Schema&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;CN=Configuration&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;DC=rightnetworks&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;DC=com&lt;/SPAN&gt; &lt;SPAN class=""&gt;name=Alertz&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;ProductFeedback&lt;/SPAN&gt; &lt;SPAN class=""&gt;distinguishedName=CN=Alertz&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;ProductFeedback&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;OU=Expired&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alert&lt;/SPAN&gt; &lt;SPAN class=""&gt;Groups&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;OU=Desk&lt;/SPAN&gt; &lt;SPAN class=""&gt;Alerts&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;OU=Security&lt;/SPAN&gt; &lt;SPAN class=""&gt;Groups&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;DC=rightnetworks&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;DC=com&lt;/SPAN&gt; &lt;SPAN class=""&gt;cn=Alertz&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;ProductFeedback&lt;/SPAN&gt; &lt;SPAN class=""&gt;Object&lt;/SPAN&gt; &lt;SPAN class=""&gt;Details:&lt;/SPAN&gt; &lt;SPAN class=""&gt;sAMAccountType=268435456&lt;/SPAN&gt; &lt;SPAN class=""&gt;sAMAccountName=Alertz&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;ProductFeedback&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;objectSid=S-1&lt;/SPAN&gt;-5-21-2605281412-2030159296-1019850961-856824&lt;/SPAN&gt; &lt;SPAN class=""&gt;objectGUID=1e0bcfbf-dc8b-43e9-855a-7004ce3d6b3b&lt;/SPAN&gt; &lt;SPAN class=""&gt;whenChanged=09:33.53&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Wed&lt;/SPAN&gt; &lt;SPAN class=""&gt;08/16/2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;whenCreated=09:31.41&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Tue&lt;/SPAN&gt; &lt;SPAN class=""&gt;08/01/2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;objectClass=top&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;group&lt;/SPAN&gt; &lt;SPAN class=""&gt;Event&lt;/SPAN&gt; &lt;SPAN class=""&gt;Details:&lt;/SPAN&gt; &lt;SPAN class=""&gt;uSNChanged=820790490&lt;/SPAN&gt; &lt;SPAN class=""&gt;uSNCreated=813674539&lt;/SPAN&gt; &lt;SPAN class=""&gt;instanceType=4&lt;/SPAN&gt; &lt;SPAN class=""&gt;Additional&lt;/SPAN&gt; &lt;SPAN class=""&gt;Details:&lt;/SPAN&gt; &lt;SPAN class=""&gt;dSCorePropagationData=16010101000000.0Z&lt;/SPAN&gt; &lt;SPAN class=""&gt;groupType=-2147483646&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 14:50:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654509#M226134</guid>
      <dc:creator>tkerr1357</dc:creator>
      <dc:date>2023-08-16T14:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: blacklist regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654551#M226140</link>
      <description>&lt;P&gt;What have you tried so far?&amp;nbsp; Is the sAMAccuontName field already properly extracted (the complete value is present)?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 20:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654551#M226140</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-16T20:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: blacklist regex help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654798#M226193</link>
      <description>&lt;P&gt;The difficult seems to be that default extraction will use pairdelim=" ". &amp;nbsp;This ends up getting just "Alertz" in sAMAccountName.&lt;/P&gt;&lt;P&gt;There are any number of ways to overcome that depending on the exact problem you are trying to solve. &amp;nbsp;Assuming by "blacklist" you mean to simply pick events with this sAMAccountName value from all events, the most efficient way is to put the criterion in index search itself.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;all other search criteria&amp;gt; "sAMAccountName=Alertz - ProductFeedback"&lt;/LI-CODE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 06:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/blacklist-regex-help/m-p/654798#M226193</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-08-18T06:57:23Z</dc:date>
    </item>
  </channel>
</rss>

