Getting Data In

How to forward only specific Windows eventlogs via Splunk Universal forwarder

chimbudp
Contributor

I need to monitor only logs with Event code = 5410,6913.
How can i setup this in forwarder ?
please suggest some help

Tags (2)
1 Solution

lukejadamec
Super Champion

This is what the book says to do...

On the forwarder, you need to enable the WinEventLog:Security input.

On the indexer you need to create entries in your system/local/props.conf and system/local/transforms.conf

props.conf

[source::*:Security]

TRANSFORMS-set=setnull,setparsing

transforms.conf

[setnull]

REGEX = .

DEST_KEY = queue

FORMAT = nullQueue

[setparsing]

REGEX =(?m)^EventCode=(5410|6913)

DEST_KEY = queue

FORMAT = indexQueue

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

As of Splunk 6, there is a simpler way to filter which Windows events are forwarded by Splunk.

See whitelist and blacklist in the "Windows Event Log Monitor" section of the following doc: http://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf

lukejadamec
Super Champion

This is what the book says to do...

On the forwarder, you need to enable the WinEventLog:Security input.

On the indexer you need to create entries in your system/local/props.conf and system/local/transforms.conf

props.conf

[source::*:Security]

TRANSFORMS-set=setnull,setparsing

transforms.conf

[setnull]

REGEX = .

DEST_KEY = queue

FORMAT = nullQueue

[setparsing]

REGEX =(?m)^EventCode=(5410|6913)

DEST_KEY = queue

FORMAT = indexQueue

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...