Getting Data In

Multiple Eventcodes in same Blacklist

helpmelearn
Explorer

Hello 

We are trying to change the below blacklists: 


blacklist3 = EventCode="4690" 
blacklist4 = EventCode="5145"
blacklist5 = EventCode="5156"
blacklist6 = EventCode="4658"
blacklist7 = EventCode="5158"

To a single blacklist with multiple eventcodes. We have tried:

blacklist3 = EventCode=5145,5156,4658,4690,5158

and

blacklist3 = EventCode="5145" OR "5156" OR "4658" OR "4690" OR "5158"

And none of these are applying and blocking out the event codes. 

 

Any recommendations on how to get this to work? 

 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax is incorrect.  A blacklist must be a comma-separated list of event IDs or pairs of key=regex specifiers.  Try this

blacklist3 = 5145,5156,4658,4690,5158
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax is incorrect.  A blacklist must be a comma-separated list of event IDs or pairs of key=regex specifiers.  Try this

blacklist3 = 5145,5156,4658,4690,5158
---
If this reply helps you, Karma would be appreciated.

helpmelearn
Explorer

Thankyou! This worked 😄 

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...