I only want to see cmd.exe and blacklist everything else for EventCode 4688.
blacklist = EventCode="4688" Message="(?:New Process Name:).+(?:cmd.exe)" will remove cmd.exe but 'Message!=' doesn't do the opposite.
Perhaps a whitelist?
whitelist = EventCode="4688" Message="(?:New Process Name:).+(?:cmd.exe)"
That does work but I have some inherited blacklists that would have made it easier (for other reasons not shown in the example) to do it in blacklist.
Perhaps a whitelist?
whitelist = EventCode="4688" Message="(?:New Process Name:).+(?:cmd.exe)"
I was really trying to do it in Blacklist due to some convoluted but prebuilt blacklists I inherited but I think I'll just have to build it out properly in the whitelist. It really is the best way to do it.