|
Hi, Had installed splunk on serverA and serverB and configured both as a forwarder to forward wineventlogs to splunk indexer. I will like to filter out certain events(eg.540) and I tried doing this on the splunk indexer itself:
Apparently it still doesn't work after doing a search the events are still shown: 1) How do I filter out event code 540? Should it be done on the forwarder itself or splunk indexer? 2) How do I filter out event code 540, only on serverA and not serverB? Thanks. |
|
Not sure if anything yet but tried shifting the configuration to the forwarder itself now as mine seems to be a heavy forwarder. Found this link to be useful: Where do I configure my Splunk settings? Seems ok but am monitoring it.If it works, it solves my problem of filtering out event codes on one server but not another as well.. |
|
Did this ever start working for you? |
