Getting Data In

Blacklist sometimes not working

tdewberry
New Member

I have this in my windows DC server with Universal Forwarder v 6.1.1.
..\Splunk_TA_Windows\local\inputs.conf file:

[WinEventLog://Security]
disabled = 0
current_only=1
blacklist1=EventCode=4662
blacklist2=EventCode=566

Yet event 4662 gets indexed sometimes. Any idea? The event 4662 is generated around 1000+ per second. Is the forwarder not keeping up with this rate of events?

Tags (3)
0 Karma

kserra_splunk
Splunk Employee
Splunk Employee

The issue here is that the blacklist requires delimiters around the regex in order for it to work. Try changing blacklist1=EventCode="4662" , for more detail please see the following post

http://answers.splunk.com/answers/148883/what-is-wrong-with-my-inputsconf-eventcode-blacklist

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...