Getting Data In

Exclude Process ID or application from Indexing

howardevak
New Member

Hi,

We have a need to exclude unwanted events from indexing. The problem is the majority of them are windows file access events which we need to monitor.

What i need to know is if we can exclude eventlogs from indexing based on a process ID or the application running them.

The backup is causing lots of unnecessary events that need excluding.

0 Karma

lguinn2
Legend

What do the events look like? What is the sourcetype and the format? What uniquely identifies these events?

Also, have you considered setting the Windows application log to exclude these events? If Windows isn't logging the details, then Splunk won't either.

0 Karma

howardevak
New Member

Many thanks for your reply Iguinn,

However my problem is this.

I need to index read and write events (which we are currently) but I want to exclude read and write events logged by a particular process (the backup application)

at the moment the backup application is accounting for 95% of all indexed items and there is no requirement for us to keep those indexed.

Can you help further ?

Kind Regards,

Howard

0 Karma

lguinn2
Legend

The answer to your question is yes. In Splunk, this is called filtering. Filtering is performed as the input data is parsed. Usually this happens on the indexer (unless you are using a heavy forwarder).

Here is a link to the relevant bit of documentation: Route and filter data

Here are some similar questions at answers.splunk.com, which show examples that may be useful to you

How do I exclude some events from being indexed by Splunk?

How do I configure Splunk to filter out events I don't want to index?

Hopefully this will help. Feel free to ask more specific questions if you need more details.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...