Splunk Enterprise Security

How to filter logs in Windows Server to decrease the quota of data in Splunk Enterprise Security (ES)?

dillencehsu
Path Finder

I using Splunk ES and I need filter logs in Windows Server(probably 200 servers) to decrease the quota of data.
In Windows Event Log, how many EventCodes is enough for Splunk Enterprise Security (ES)?
Do you need a list with EventCode?

Thanks : )

0 Karma
1 Solution

adonio
Ultra Champion

hello there,

i think you are looking at it backwards.
try to ask yourself, "what data do i need to see?" or "what security related questions i have?"
find out which windows event codes answer those questions and collect them.
another way to approach it, considering you are using only pre-built correlation searches and do not care about developing your own set of rules, is to open the correlation searches, see what they are searching against (most of the time data models) see how the data models are created, leveraging tags, see which tags are assigned to each event code, and filter the event codes that does not have the relevant tags
in any case, there are also another ways to decrease the volume of windows events in order to save on license
i think there is even an app for that: https://splunkbase.splunk.com/app/3500/

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there,

i think you are looking at it backwards.
try to ask yourself, "what data do i need to see?" or "what security related questions i have?"
find out which windows event codes answer those questions and collect them.
another way to approach it, considering you are using only pre-built correlation searches and do not care about developing your own set of rules, is to open the correlation searches, see what they are searching against (most of the time data models) see how the data models are created, leveraging tags, see which tags are assigned to each event code, and filter the event codes that does not have the relevant tags
in any case, there are also another ways to decrease the volume of windows events in order to save on license
i think there is even an app for that: https://splunkbase.splunk.com/app/3500/

hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...

Index This | What is feather-light but cannot be held long?

May 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

.conf26 Registration is Live: Secure Your Early Bird Pass Now

  Lock in Your Spot: Registration Open for .conf26 in Denver Hello Splunkers, I have exciting news! Your ...