I have configure the input file residing under following path.C:\Program Files\SplunkUniversalForwarder\etc\system\local.
Configuration:
[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 1
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist1 = EventCode="5156" Message="*"
Requirement:
I want all security events logs other than event code 5156........Is my configuration wrong.
Just use blacklist = 5156
. No need to complicate it the way you did.
HI Frank!
Thanks for reply.I am still receiving logs with event code 5156.Please review my updated configuration.
[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist = EventCode=5156
I have tried this as well
[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist =5156
Exactly. Whitelist and blacklist for WinEventLog can filter for specific eventIDs by just specifying the IDs (comma separated). No need to use Eventcode=
etc. Just the code itself. Please try that, make sure to restart splunk after adjusting it.