Getting Data In

How to blacklist events for a specific event code and task category?

nmohammed
Builder

Trying to blacklist specific windows event logs based on event code and task category, but doesn't work .

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = winevents
renderXml=false
blacklist1=EventCode="5145" TaskCategory="(Detailed File Share|File Share)"

Example event - 

07/13/2018 11:22:01 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=5140
EventType=0
Type=Information
ComputerName=SomeServer
TaskCategory=File Share
OpCode=Info
RecordNumber=5487448804
Keywords=Audit Success
Message=A network share object was accessed.

Subject:
    Security ID:        S-1-5-21-xxxxxxxxx-xxxxxx-xxxxxx-xxxx
    Account Name:       cz9_rmc_s3_CIFS$
    Account Domain:     domain
    Logon ID:       0x3D9AC95C1

Network Information:    
    Object Type:        File
    Source Address:     10.xxx.xx.xxx
    Source Port:        45088

Share Information:
    Share Name:     \\*\IPC$
    Share Path:     

Access Request Information:
    Access Mask:        0x1
    Accesses:       ReadData (or ListDirectory)
0 Karma
1 Solution

CarsonZa
Contributor

try this

blacklist=EventCode=%^5145$% TaskCategory=%(Detailed File Share|File Share)%

View solution in original post

somesoni2
Revered Legend

Try using just blacklist instead of blacklist1. You can have upto 10 blacklist filters applied but it should start with blacklist, blacklist1, blacklist2...etc till blacklist9.

0 Karma

nmohammed
Builder

Tried this -

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = winevents
renderXml=false
blacklist1=EventCode="5145" TaskCategory="Detailed File Share"
blacklist1=EventCode="5145" TaskCategory="File Share"

Did not work. Still see the events come in.

0 Karma

CarsonZa
Contributor

try this

blacklist=EventCode=%^5145$% TaskCategory=%(Detailed File Share|File Share)%

gurulee
Explorer

Thank you for sharing. I found this helpful.

0 Karma

nmohammed
Builder

Actually this worked. I had two different EventCodes sending the Same Category.

Thanks @CarsonZa

nmohammed
Builder

Thanks , I tried it as well.. Did not work , still see the events come in.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...