Getting Data In

WinRegMon Blacklist specific Registry Hive

DanielAmlung
Path Finder

Hi,

i currently use the WinRegMon Stanza within the inputs.conf. Currently i monitor all changes within the User Software Hive. But there is one Path that i want to exclude. So i tried using the blacklist feature, but it didnt work. See my config attached:

hive = \REGISTRY\USER\.\Software\\?.
blacklist1 = \REGISTRY\USER\.\Software\Classes\.\MuiCache\\?.*
proc=.*

That blacklist doesnt work - can someone spot the failure?

Thanks in advance

0 Karma
1 Solution

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

View solution in original post

spayneort
Contributor

blacklist1 is for event logs, not registry monitoring. You could change your hive regex to exclude the unwanted path but include the others.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...