Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit my WinEventLog blacklist configuration to exclude AccountNames in Windows Security logs from getting indexed?

$
0
0
I am trying to remove generic service account names from the Windows Security log, so that we can focus on indexing only the specific user accounts. Am I missing something in my inputs.conf? [WinEventLog://Security] disabled = 0 index = "index" sourcetype = "sourcetype" blacklist = Account_Name=name1| name2|name3|name4|name5 Thank you in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>