Getting Data In

How to blacklist events for a specific event code and task category?

nmohammed
Builder

Trying to blacklist specific windows event logs based on event code and task category, but doesn't work .

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = winevents
renderXml=false
blacklist1=EventCode="5145" TaskCategory="(Detailed File Share|File Share)"

Example event - 

07/13/2018 11:22:01 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=5140
EventType=0
Type=Information
ComputerName=SomeServer
TaskCategory=File Share
OpCode=Info
RecordNumber=5487448804
Keywords=Audit Success
Message=A network share object was accessed.

Subject:
    Security ID:        S-1-5-21-xxxxxxxxx-xxxxxx-xxxxxx-xxxx
    Account Name:       cz9_rmc_s3_CIFS$
    Account Domain:     domain
    Logon ID:       0x3D9AC95C1

Network Information:    
    Object Type:        File
    Source Address:     10.xxx.xx.xxx
    Source Port:        45088

Share Information:
    Share Name:     \\*\IPC$
    Share Path:     

Access Request Information:
    Access Mask:        0x1
    Accesses:       ReadData (or ListDirectory)
0 Karma
1 Solution

CarsonZa
Contributor

try this

blacklist=EventCode=%^5145$% TaskCategory=%(Detailed File Share|File Share)%

View solution in original post

somesoni2
Revered Legend

Try using just blacklist instead of blacklist1. You can have upto 10 blacklist filters applied but it should start with blacklist, blacklist1, blacklist2...etc till blacklist9.

0 Karma

nmohammed
Builder

Tried this -

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = winevents
renderXml=false
blacklist1=EventCode="5145" TaskCategory="Detailed File Share"
blacklist1=EventCode="5145" TaskCategory="File Share"

Did not work. Still see the events come in.

0 Karma

CarsonZa
Contributor

try this

blacklist=EventCode=%^5145$% TaskCategory=%(Detailed File Share|File Share)%

gurulee
Explorer

Thank you for sharing. I found this helpful.

0 Karma

nmohammed
Builder

Actually this worked. I had two different EventCodes sending the Same Category.

Thanks @CarsonZa

nmohammed
Builder

Thanks , I tried it as well.. Did not work , still see the events come in.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...