Getting Data In

WMI filter doesn't work

alain_bettiol
New Member

Hello, I try to modify the behaviour of a forwarder installed on a Windows server. I would like to prevent the forwarder from sending WINDOWS events EventType=4
I have tried everything but still doesn't work, all EventTypes (1, 2,3, 4) are still forwarded

Thanks for your help

My props.conf is :
[WMI:WinEventLog:System]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Security]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Application]
TRANSFORMS-wmi=wminullEvents

Transforms.conf is :
[wminullEvents]
REGEX=(?msi)^EventType=(4)
DEST_KEY=queue
FORMAT=nullQueue

Tags (2)
0 Karma

alain_bettiol
New Member

I have found the cause, the default setup doesn't forward anything I have enabled sources in the manageR Now the events are forwarded by the heavy forwarder but the filtering doesn't work, everything is forwarded.

0 Karma

alain_bettiol
New Member

I have installed the heavy forwarder but it doesn't forward any event.
I didn't configure props.conf and transforms.conf yet.
The process splunkd is running and config file outputs.conf seems correct.
Is there a logfile I can check to understand what happens ?
Thanks

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

A Universal Forwarder cannot do filtering based on the event content, you need a Heavy Forwarder for that.

0 Karma

alain_bettiol
New Member

Splunk Universal Forwarder 5.0.2 (build 149561)

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Run this:

$SPLUNK_HOME/bin/splunk version
0 Karma

alain_bettiol
New Member

No I don't think so. I'm not sure but I think it is light forwarder. How can I recognize a heavy or light forwarder?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is this on a heavy forwarder?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...