Getting Data In

I want to filter specific security events logs but my configuration didn't work.

aqudoos
Explorer

I have configure the input file residing under following path.C:\Program Files\SplunkUniversalForwarder\etc\system\local.

Configuration:

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 1
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist1 = EventCode="5156" Message="*"

Requirement:

I want all security events logs other than event code 5156........Is my configuration wrong.

0 Karma

FrankVl
Ultra Champion

Just use blacklist = 5156. No need to complicate it the way you did.

0 Karma

aqudoos
Explorer

HI Frank!

Thanks for reply.I am still receiving logs with event code 5156.Please review my updated configuration.

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist = EventCode=5156

0 Karma

aqudoos
Explorer

I have tried this as well

[WinEventLog://Security]
disabled = 0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
blacklist =5156

0 Karma

FrankVl
Ultra Champion

Exactly. Whitelist and blacklist for WinEventLog can filter for specific eventIDs by just specifying the IDs (comma separated). No need to use Eventcode= etc. Just the code itself. Please try that, make sure to restart splunk after adjusting it.

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...