Getting Data In

WinRegMon Blacklist specific Registry Hive

DanielAmlung
Explorer

Hi,

i currently use the WinRegMon Stanza within the inputs.conf. Currently i monitor all changes within the User Software Hive. But there is one Path that i want to exclude. So i tried using the blacklist feature, but it didnt work. See my config attached:

hive = \REGISTRY\USER\.\Software\\?.
blacklist1 = \REGISTRY\USER\.\Software\Classes\.\MuiCache\\?.*
proc=.*

That blacklist doesnt work - can someone spot the failure?

Thanks in advance

0 Karma
1 Solution

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

View solution in original post

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...