On the universal forwarders, I need a regex pattern to drop Powershell temporary script events in splunk. I'm trying to use the "Message" object to filter out the following example:
Script Name = C:\\WINDOWS\\CCM\\SystemTemp\\1b71bac2-99a4-4075-a96e-9ecc803443f5.ps1
So far, my blacklist stanza is:
blacklist1 = EventCode = "4103" Message="C:\\\\WINDOWS\\\\CCM\\\\SystemTemp\\\\.*\.ps1"
But this does not seem to work. Help please!
Your regex looks close, but the Message field may not match the exact path format. Before and after the path, and verify the raw event to confirm how Message is stored. Testing the regex against the raw event usually reveals the mismatch.
Hi @Lynn_01
I think you need to adjust the formatting of your blacklist entry in inputs.conf.
Remove the spaces around the inner = characters and the over-escaping of the backslashes.
[WinEventLog://Microsoft-Windows-PowerShell/Operational] ...
... blacklist1 = EventCode="4103" Message="C:\\WINDOWS\\CCM\\SystemTemp\\.*\.ps1
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.
Thank you for the response.
Do you think:
blacklist1 = EventCode="4103" Message="C:\\WINDOWS\\CCM\\SystemTemp\\[0-9|a-z]{8}\-([0-9|a-z]{4}\-){3}[0-9|a-z]{12}\.ps1
Would work to only filter out the specific number/word character syntax these temporary scripts use and allow other .ps1 scripts to be ingested?