I was wondering if there is a way to filter the event codes when you try to index exported EVTX, I've tried with whitelist with no luck.
Any help will be highly appreciated.
What regular expression you used for whitelistiing? Also you can try out filtering events queues., refer below docs:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Forwarding/Routeandfilterdatad#Keep_specific_event...