Getting Data In

WinRegMon Blacklist specific Registry Hive

DanielAmlung
Path Finder

Hi,

i currently use the WinRegMon Stanza within the inputs.conf. Currently i monitor all changes within the User Software Hive. But there is one Path that i want to exclude. So i tried using the blacklist feature, but it didnt work. See my config attached:

hive = \REGISTRY\USER\.\Software\\?.
blacklist1 = \REGISTRY\USER\.\Software\Classes\.\MuiCache\\?.*
proc=.*

That blacklist doesnt work - can someone spot the failure?

Thanks in advance

0 Karma
1 Solution

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

View solution in original post

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...