How do I configure a forwarder to whitelist only Event Code 4624 and Logon Types 2 or 11?

New Member

I'm trying to edit inputs.conf in my forwarder to show ONLY Event 4624, with only Logon Type 2 or 11. I've seen many examples online of similar things, but nothing has worked for me so far. I understand I need to parse the Logon Type out of the Message field.

What would I have to add to this:

whitelist1 = EventCode="4624" Message="what's here?"

0 Karma

New Member

One of my coworkers may have come up with the answer:

whitelist1 = EventCode=4624 Message="Logon Type:\s+[2, 11]"

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!