Getting Data In

Can Universal Forwaders filter in their input.conf file?

splunktrainingu
Communicator

I am attempting to filter an eventID 5156 with an application name of "\device\harddiskvolume5\program files\bonjour\mdnsresponder.exe" I am using a Universal Forwarder but I am seeing mixed responses saying this is not possible on universal Forwarder. My Universal Forwarders point to my Indexer.

Labels (1)
0 Karma
1 Solution

dsctm3
Path Finder

Check this out.

https://www.splunk.com/en_us/blog/tips-and-tricks/controlling-4662-messages-in-the-windows-security-...

I think this is along the line of what you are looking for. You need to use regex to create the filter.

(Edit: Formatting)

View solution in original post

0 Karma

dsctm3
Path Finder

Check this out.

https://www.splunk.com/en_us/blog/tips-and-tricks/controlling-4662-messages-in-the-windows-security-...

I think this is along the line of what you are looking for. You need to use regex to create the filter.

(Edit: Formatting)

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...