Getting Data In

How to filter events from Eventlog?

infra4scc
New Member

We are using the Splunk Universal Forwarder on Windows servers to capture event viewer logs into Splunk.  We have a known issue with a product causing a large number of events to be recorded in the event viewer which are then sent into Splunk.  How can we filter out a specific event from the Universal Forwarder so that it is not sent into Splunk?

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

See this document.

https://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf#Event_Log_filtering

Just be aware that there are two different formats and you use one of them depending on whether you ingest your events in "old style" plain text format or as XML.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...