Getting Data In

How to filter Windows Security events by changing inputs conf


I have made the following changes in my inputs.conf. However no luck
Could anyone help me with this?


However the above whitelist filter did not work at all. Specifically I dont want Eventcode 4674 events. So I have omitted it in whitelist.But events with 4674 are not getting filtered.

Possible tries:

Do I need to specify blacklist?
Do I mention like this "Eventcode=4566" ?
Do I use anyother stanza to achieve this?

Thanks in advance.

Tags (2)
0 Karma


As you've not mentioned it, did you check that the UF installed on that machine is actually version 6?

0 Karma

Path Finder

Found my problem.. between events I had one entry with two commas in a row, which made it not work.. all good.

0 Karma


Many thanks for the reply.

Yes. I have tried both whitelist and blacklist.
Still the filter did not work.
I have also tried to include evt_resolve_ad_obj = 1 in my inputs.conf.
However that also doesn't seem to work.
Could anyone please suggest any other possibilities to filter events based on event codes?

0 Karma

Path Finder

Same problem.. whitelisting doesn't work. I would think that if you whitelist certain events everything else is blocked but not working for me either.

0 Karma

Path Finder

Hello there,

Have you tried using blacklist instead of whitelist?

There's a good blog you can read here:

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...