Getting Data In

Is there a limit on the amount of blacklist entries under [WinEventLog://Security]?

DJAXX03
New Member

Is there a limit on the amount of blacklist entries that can be placed under " [WinEventLog://Security]" stanza.
It looks like I can only add 9 entries (blacklist1= to blacklist9=) If I add blacklist10= the line is ignored.

For example, the following format works.

[WinEventLog://Security]
blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)"
blacklist3 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist4 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist5 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist6 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist7 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist8 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX"
blacklist9 = EventCode=%^(4658|4663|5145|5156|5157)$%

If I add an additional blacklist10=, the line is ignored and the events are logged.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Admin manual says "Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through whitelist9 and blacklist1 through blacklist9 are supported." So it would seem your experience is consistent with the documentation.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

jotne
Builder
Spoiler
You can overcome this by combining list, like blacklist1 and 2 can combine to 1 like this.

blacklist1 = EventCode="566|4662" Message="Object Type:\s+(?!groupPolicyContainer)"
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Admin manual says "Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through whitelist9 and blacklist1 through blacklist9 are supported." So it would seem your experience is consistent with the documentation.

---
If this reply helps you, Karma would be appreciated.

mmoore723
Engager

Event Log filtering

Filtering at the input layer is desirable to reduce the total

processing load in network transfer and computation on the Splunk

nodes that acquire and processing Event Log data.

whitelist = | key=regex [key=regex]
blacklist = | key=regex [key=regex]

whitelist1 = | key=regex [key=regex]
whitelist2 = | key=regex [key=regex]
whitelist3 = | key=regex [key=regex]
whitelist4 = | key=regex [key=regex]
whitelist5 = | key=regex [key=regex]
whitelist6 = | key=regex [key=regex]
whitelist7 = | key=regex [key=regex]
whitelist8 = | key=regex [key=regex]
whitelist9 = | key=regex [key=regex]
blacklist1 = | key=regex [key=regex]
blacklist2 = | key=regex [key=regex]
blacklist3 = | key=regex [key=regex]
blacklist4 = | key=regex [key=regex]
blacklist5 = | key=regex [key=regex]
blacklist6 = | key=regex [key=regex]
blacklist7 = | key=regex [key=regex]
blacklist8 = | key=regex [key=regex]
blacklist9 = | key=regex [key=regex]

  • These settings are optional.
  • Both numbered and unnumbered whitelists and blacklists support two formats:

    • A comma-separated list of event IDs.
    • A list of key=regular expression pairs.
    • You cannot combine these formats. You can use either format on a specific line.
  • Numbered whitelist settings are permitted from 1 to 9, so whitelist1 through
    whitelist9 and blacklist1 through blacklist9 are supported.

  • If no whitelist or blacklist rules are present, the input reads all events.

http://docs.splunk.com/Documentation/Splunk/7.1.0/Admin/Inputsconf#Windows_Event_Log_Monitor

0 Karma

ibondarets
Explorer

Was it addressed in 6.5?

0 Karma

DJAXX03
New Member

Rich,

I was hoping there was a better answer as I would rather filter on specific criteria associated with a Windows ID instead of all events per Windows ID. This limitation forces me to be less granular with filtering options.

Thanks for the the quick reply and information.

0 Karma
Get Updates on the Splunk Community!

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...