Getting Data In

WinRegMon Blacklist specific Registry Hive

DanielAmlung
Path Finder

Hi,

i currently use the WinRegMon Stanza within the inputs.conf. Currently i monitor all changes within the User Software Hive. But there is one Path that i want to exclude. So i tried using the blacklist feature, but it didnt work. See my config attached:

hive = \REGISTRY\USER\.\Software\\?.
blacklist1 = \REGISTRY\USER\.\Software\Classes\.\MuiCache\\?.*
proc=.*

That blacklist doesnt work - can someone spot the failure?

Thanks in advance

0 Karma
1 Solution

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

View solution in original post

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...