Getting Data In
Highlighted

Filter WinEventLog

New Member

Hi, i need of the filter for Windows Logs, in Splunk Web, ok....more i need in inputs in each machine.
TaskCategory="Logon" OR "logoff" LogonType="2" OR LogonType="3" OR LogonType="10" OR LogonType="11"

thanks..

Tags (1)
0 Karma
Highlighted

Re: Filter WinEventLog

Path Finder

I'm not sure what you're asking for. I tried the search below on our system and it works fine:

index="main" (TaskCategory="Logon" OR TaskCategory="logoff") (LogonType="2" OR LogonType="3" OR LogonType="10" OR LogonType="11")

Are you getting the events you want?

Note that your search: TaskCategory="Logon" OR "logoff" will get any events that contain the work "logoff", even if they are not in the TaskCategory field.

You might want to use (TaskCategory="Logon" OR TaskCategory="logoff")

0 Karma
Highlighted

Re: Filter WinEventLog

New Member

Thanks...
I need to use this filter in transforms.conf and propos.conf the file, however it's not working.

0 Karma
Highlighted

Re: Filter WinEventLog

New Member

Thanks...
I need to use this filter in transforms.conf and propos.conf the file, however it's not working.

0 Karma
Highlighted

Re: Filter WinEventLog

Ultra Champion

The props/transforms only apply when the events are parsed, so only on the indexers (or heavy forwarders)
It will not work in the universal or lightweight forwarders.

0 Karma