- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

splunktrainingu
Communicator
04-30-2020
12:09 PM
I am attempting to filter an eventID 5156 with an application name of "\device\harddiskvolume5\program files\bonjour\mdnsresponder.exe" I am using a Universal Forwarder but I am seeing mixed responses saying this is not possible on universal Forwarder. My Universal Forwarders point to my Indexer.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

dsctm3
Path Finder
04-30-2020
01:19 PM
Check this out.
I think this is along the line of what you are looking for. You need to use regex to create the filter.
(Edit: Formatting)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

dsctm3
Path Finder
04-30-2020
01:19 PM
Check this out.
I think this is along the line of what you are looking for. You need to use regex to create the filter.
(Edit: Formatting)
