Splunk Search

filter windows application event by Source

ajaysamantbms
Explorer

I am using windows TA app to get events from windows event log.
The windows events are coming inside Indexer.

But i would like to filter them at universal forwarder if possible and get events for a particular source only - and not for all Applications - looking for specific values under "Source"

Source tells me that event is coming from which Application. So i want events only from Source=A and Source=B from windows application event log

Tags (1)
0 Karma

somesoni2
Revered Legend

See the link below with similar requirement (except that this post is filtering based on EventCode)

http://answers.splunk.com/answers/47168/windows-event-log-filter-attempt-failing

Also, note the fact that this changes have to be done on Indexer as you're using Universal Forwarder.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...