Getting Data In

Filtering Windows Events using XML in inputs.conf

New Member

Somobody has experience with filtering (supressing) Windows event using XML in Splunk inputs.conf?

So I have XML to filter specific Events from logs. I can't find in documentation stanza for adding XML in inputs.conf

Is it possible at all or only blacklisting?

Thank you

0 Karma


Hi @marcoatto 

whitelist/blacklist are the only options to filter winevents, if your XML associated to a key ( Ex. EventCode) then using Regex you can filter them as defined in specs here -


An upvote would be appreciated and Accept solution if it helps!

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!