Getting Data In

WMI filter doesn't work

alain_bettiol
New Member

Hello, I try to modify the behaviour of a forwarder installed on a Windows server. I would like to prevent the forwarder from sending WINDOWS events EventType=4
I have tried everything but still doesn't work, all EventTypes (1, 2,3, 4) are still forwarded

Thanks for your help

My props.conf is :
[WMI:WinEventLog:System]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Security]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Application]
TRANSFORMS-wmi=wminullEvents

Transforms.conf is :
[wminullEvents]
REGEX=(?msi)^EventType=(4)
DEST_KEY=queue
FORMAT=nullQueue

Tags (2)
0 Karma

alain_bettiol
New Member

I have found the cause, the default setup doesn't forward anything I have enabled sources in the manageR Now the events are forwarded by the heavy forwarder but the filtering doesn't work, everything is forwarded.

0 Karma

alain_bettiol
New Member

I have installed the heavy forwarder but it doesn't forward any event.
I didn't configure props.conf and transforms.conf yet.
The process splunkd is running and config file outputs.conf seems correct.
Is there a logfile I can check to understand what happens ?
Thanks

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

A Universal Forwarder cannot do filtering based on the event content, you need a Heavy Forwarder for that.

0 Karma

alain_bettiol
New Member

Splunk Universal Forwarder 5.0.2 (build 149561)

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Run this:

$SPLUNK_HOME/bin/splunk version
0 Karma

alain_bettiol
New Member

No I don't think so. I'm not sure but I think it is light forwarder. How can I recognize a heavy or light forwarder?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is this on a heavy forwarder?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...