Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is there a lmit on the amount of blacklist entries under [WinEventLog://Security]?

$
0
0
Is there a limit on the amount of blacklist entries that can be placed under " [WinEventLog://Security]" stanza. It looks like I can only add 9 entries (blacklist1= to blacklist9=) If I add blacklist10= the line is ignored. For example, the following format works. [WinEventLog://Security] blacklist1 = EventCode="4662" Message="Object Type:\s+(?!groupPolicyContainer)" blacklist2 = EventCode="566" Message="Object Type:\s+(?!groupPolicyContainer)" blacklist3 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist4 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist5 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist6 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist7 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist8 = EventCode="XXX" Message="XXXXXXXXXXXXXXXXXX" blacklist9 = EventCode=%^(4658|4663|5145|5156|5157)$% If I add an additional blacklist10=, the line is ignored and the events are logged.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>