Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to Blacklist on UF with a TCP input

$
0
0
I have a UF running on a linux device, with a TCP input. The input is coming from a Graylog forwarder and all the windows events coming with a 'winlogbeat_ preface. I want to black list windows events coming by event code and normally I use a blacklist -= EventCode="xxxx" Message=.... however the eventcode comes in as winlogbeat_event_id, I did try this: blacklist1= winlogbeat_event_id = "4662" This doesn't appear to work. Can someone help with this? Is there anylog that shows events being whitelisted or blacklisted? Thank You!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>