Splunk Search

Blacklist WinEventLog::/Security with user names ending in $

ericrenfro
New Member

I'm trying to get a blacklisted log entry that works on Universal Forwarders to filter out specific event codes with user fields that end in $ in their value.

What I have now, works on my test environment with uploaded sample logs, but not directly on the Universal Forwarder itself:

blacklist1 = EventCode="(4624|4634)" user=".*\$"
blacklist2 = EventCode="4672" Account_Name=".*\$"

What can I do to get this right so it actually works? I know that in the event log, raw, the matching line actually is space indented and something like:

...
Subject:
  Security ID:    S-1-5-18
  Account Name:   something$
  Account Domain:   domain
...

Thank you!

0 Karma

spayneort
Contributor

Try these:

blacklist1 = EventCode="4624" Message="(?ms)New\sLogon:.*?Account\sName:[^\n]+\$$"
blacklist2 = EventCode="(4634|4672)" Message="(?m)Account\sName:[^\n]+\$$"
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...