@spayneort Got this to work with similar syntax blacklist1 = EventCode="^468$" Message="Process Name:(.*?(SplunkUniversalForwarder|or_any_other_program))" Note the following: 1. The | is an OR 2. This finds anything the starts with your program 3. be careful of spaces, sometimes they don't really exist 4. Don't use $ as you'll need a wild card to find what you're looking for, plus more processing power required. Hope that helps!
... View more