Getting Data In

WMI filter doesn't work

alain_bettiol
New Member

Hello, I try to modify the behaviour of a forwarder installed on a Windows server. I would like to prevent the forwarder from sending WINDOWS events EventType=4
I have tried everything but still doesn't work, all EventTypes (1, 2,3, 4) are still forwarded

Thanks for your help

My props.conf is :
[WMI:WinEventLog:System]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Security]
TRANSFORMS-wmi=wminullEvents

[WMI:WinEventLog:Application]
TRANSFORMS-wmi=wminullEvents

Transforms.conf is :
[wminullEvents]
REGEX=(?msi)^EventType=(4)
DEST_KEY=queue
FORMAT=nullQueue

Tags (2)
0 Karma

alain_bettiol
New Member

I have found the cause, the default setup doesn't forward anything I have enabled sources in the manageR Now the events are forwarded by the heavy forwarder but the filtering doesn't work, everything is forwarded.

0 Karma

alain_bettiol
New Member

I have installed the heavy forwarder but it doesn't forward any event.
I didn't configure props.conf and transforms.conf yet.
The process splunkd is running and config file outputs.conf seems correct.
Is there a logfile I can check to understand what happens ?
Thanks

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

A Universal Forwarder cannot do filtering based on the event content, you need a Heavy Forwarder for that.

0 Karma

alain_bettiol
New Member

Splunk Universal Forwarder 5.0.2 (build 149561)

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Run this:

$SPLUNK_HOME/bin/splunk version
0 Karma

alain_bettiol
New Member

No I don't think so. I'm not sure but I think it is light forwarder. How can I recognize a heavy or light forwarder?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is this on a heavy forwarder?

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...