Hi @bkwoka .
Is the end result to capture specific EventCodes? EventCodes can be included in whitelists/blacklists:
https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorWindowseventlogdata#Create_advanced_filters_with_.27whitelist.27_and_.27blacklist.27
... View more
Go to http://docs.splunk.com/Documentation/Splunk then in the upper right corner of the page select 6.4.2 from the drop down menu. Then under the Getting Started tab, second link down is Release Notes.
... View more