Hi
I'm filtering windows events from the Heavy Forwarder, everything works fine, all events are filtered except for EventCode = 0 any idea why?
splunkcol_1-1628884389005.png
splunkcol_2-1628884418013.png
EventCode 0 was not being filtered because it is an Application event and not a security event.
In this way I solved it
props.conf
[source::WinEventLog:Application]
TRANSFORMS-wmi = setnull2
transforms.conf
[setnull2]
REGEX= (?msi) ^EventCode=(0)
DEST_KEY=queue
FORMAT=nullQueue
EventCode 0 was not being filtered because it is an Application event and not a security event.
In this way I solved it
props.conf
[source::WinEventLog:Application]
TRANSFORMS-wmi = setnull2
transforms.conf
[setnull2]
REGEX= (?msi) ^EventCode=(0)
DEST_KEY=queue
FORMAT=nullQueue
We were able to filter it out from the UF using the following in our inputs.conf:
[WinEventLog://Application]
disabled = 0
index = windows_index
blacklist1 = EventCode="0"