Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

PowerShell Logging- Blacklist everything except Event Code 4104 & Level: Warning

$
0
0
We are attempting to ingest server powershell logging into Splunk. We found that ingest all the data was noisy and want to reduce the data ingested to what we really care about. Our goal is to only ingest Event Code 4104 with the level: Warning. Is there a way to blacklist everything, and then whitelist only Event Code 4104 with the level: Warning? We are ingesting via here: [WinEventLog://Microsoft-Windows-PowerShell/Operational]

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>