On the universal forwarders, I need a regex pattern to drop Powershell temporary script events in splunk. I'm trying to use the "Message" object to filter out the following example:
Script Name = C:\\WINDOWS\\CCM\\SystemTemp\\1b71bac2-99a4-4075-a96e-9ecc803443f5.ps1
So far, my blacklist stanza is:
blacklist1 = EventCode = "4103" Message="C:\\\\WINDOWS\\\\CCM\\\\SystemTemp\\\\.*\.ps1"
But this does not seem to work. Help please!
Hi @Lynn_01
I think you need to adjust the formatting of your blacklist entry in inputs.conf.
Remove the spaces around the inner = characters and the over-escaping of the backslashes.
[WinEventLog://Microsoft-Windows-PowerShell/Operational] ...
... blacklist1 = EventCode="4103" Message="C:\\WINDOWS\\CCM\\SystemTemp\\.*\.ps1
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.