Getting Data In

Is there a limit on the amount of blacklist entries under [WinEventLog://Security]?

DJAXX03
New Member

Is there a limit on the amount of blacklist entries that can be placed under " [WinEventLog://Security]" stanza.
It looks like I can only add 9 entries (blacklist1= to blacklist9=) If I add blacklist10= the line is ignored.

For example, the following format works.

[WinEventLog://Security]
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist3 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist4 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist5 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist6 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist7 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist8 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist9 = EventCode=%^(4658|4663|5145|5156|5157)$%

If I add an additional blacklist10=, the line is ignored and the events are logged.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Admin manual says "Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through whitelist9 and blacklist1 through blacklist9 are supported." So it would seem your experience is consistent with the documentation.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

jotne
Builder
Spoiler
You can overcome this by combining list, like blacklist1 and 2 can combine to 1 like this.

blacklist1 = EventCode="566|4662" Message="Object Type:\s+(?!groupPolicyContainer)"
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Admin manual says "Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through whitelist9 and blacklist1 through blacklist9 are supported." So it would seem your experience is consistent with the documentation.

---
If this reply helps you, Karma would be appreciated.

mmoore723
Engager

Event Log filtering

Filtering at the input layer is desirable to reduce the total

processing load in network transfer and computation on the Splunk

nodes that acquire and processing Event Log data.

whitelist = | key=regex [key=regex]
blacklist = | key=regex [key=regex]

whitelist1 = | key=regex [key=regex]
whitelist2 = | key=regex [key=regex]
whitelist3 = | key=regex [key=regex]
whitelist4 = | key=regex [key=regex]
whitelist5 = | key=regex [key=regex]
whitelist6 = | key=regex [key=regex]
whitelist7 = | key=regex [key=regex]
whitelist8 = | key=regex [key=regex]
whitelist9 = | key=regex [key=regex]
blacklist1 = | key=regex [key=regex]
blacklist2 = | key=regex [key=regex]
blacklist3 = | key=regex [key=regex]
blacklist4 = | key=regex [key=regex]
blacklist5 = | key=regex [key=regex]
blacklist6 = | key=regex [key=regex]
blacklist7 = | key=regex [key=regex]
blacklist8 = | key=regex [key=regex]
blacklist9 = | key=regex [key=regex]

  • These settings are optional.
  • Both numbered and unnumbered whitelists and blacklists support two formats:

    • A comma-separated list of event IDs.
    • A list of key=regular expression pairs.
    • You cannot combine these formats. You can use either format on a specific line.
  • Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through
    whitelist9 and blacklist1 through blacklist9 are supported.

  • If no whitelist or blacklist rules are present, the input reads all events.

http://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Inputsconf#Windows_Event_Log_Monitor

0 Karma

ibondarets
Explorer

Was it addressed in 6.5?

0 Karma

DJAXX03
New Member

Rich,

I was hoping there was a better answer as I would rather filter on specific criteria associated with a Windows ID instead of all events per Windows ID. This limitation forces me to be less granular with filtering options.

Thanks for the the quick reply and information.

0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...