Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

How to blacklist indexing a security event based on the Account Name?

$
0
0
I'm running the Splunk Universal Forwarder and I've configured the inputs.conf for the Splunk Add-on for Microsoft Windows to monitor the Security event logs for Windows. At this time though I'm looking to blacklist / not index any security event that displays a specific account name. The account name is "wilmsplunksvc". I've went ahead and created a blacklist within the inputs.conf without any luck. Below is the syntax I used. blacklist4 = Account_Name="wilmsplunksvc" Any assistance would be greatly appreciated.

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>