Splunk Search

filter windows application event by Source

ajaysamantbms
Explorer

I am using windows TA app to get events from windows event log.
The windows events are coming inside Indexer.

But i would like to filter them at universal forwarder if possible and get events for a particular source only - and not for all Applications - looking for specific values under "Source"

Source tells me that event is coming from which Application. So i want events only from Source=A and Source=B from windows application event log

Tags (1)
0 Karma

somesoni2
Revered Legend

See the link below with similar requirement (except that this post is filtering based on EventCode)

http://answers.splunk.com/answers/47168/windows-event-log-filter-attempt-failing

Also, note the fact that this changes have to be done on Indexer as you're using Universal Forwarder.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...