Getting Data In

How to filter Windows event logs from a Universal Forwarder

mokeefe
New Member

Using 5.0.2. I am receiving Windows Event Logs at the Indexer from Universal Forwarders on Windows servers. I want to filter out or send to a null queue uninteresting Windows events, so I only see Error, Warning and Critical events.

I know this needs to be in the props.conf and transforms.conf but can't get it to work.

0 Karma

Lowell
Super Champion

mokeefe
New Member

Yes, I know I can't do it at the UF, but I want to drop the events on the Indexer before they get indexed.

Thanks

0 Karma

Ayn
Legend

You cannot filter events on a Universal Forwarder. Event filtering can only occur on Splunk instances that perform parsing, which Universal Forwarder doesn't (and can't) do. You need to either setup filtering on the indexer, or switch to a heavy forwarder instead of a Universal Forwarder.

Ayn
Legend

Your question title announces the question is regarding filtering the events on a UF, so...

If you want help with the specific details you need to provide us with more information than that it "didn't work" - it's impossible to know exactly what you tried and what the exact result was. General info on event filtering is available here: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Keep_specific_events_a...

mokeefe
New Member

Yes, I know I can't do it at the UF, but I want to drop the events on the Indexer before they get indexed.

Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...