Merge pull request #427 from clong/nullqueue2
Add some Splunk nullQueues for noisy events
This commit is contained in:
@@ -21,4 +21,8 @@ TIME_FORMAT = %s
|
|||||||
TRUNCATE = 0
|
TRUNCATE = 0
|
||||||
|
|
||||||
[osquery:status]
|
[osquery:status]
|
||||||
TRANSFORMS-null = setnull
|
TRANSFORMS-null = setnull
|
||||||
|
|
||||||
|
[WinEventLog]
|
||||||
|
TRANSFORMS-null = osqueryd_wineventlog_null
|
||||||
|
TRANSFORMS-null = autoruns_wineventlog_null
|
||||||
@@ -17,4 +17,14 @@ FORMAT = host::$1
|
|||||||
[setnull]
|
[setnull]
|
||||||
REGEX = Error\scasting
|
REGEX = Error\scasting
|
||||||
DEST_KEY = queue
|
DEST_KEY = queue
|
||||||
|
FORMAT = nullQueue
|
||||||
|
|
||||||
|
[osqueryd_wineventlog_null]
|
||||||
|
REGEX = "Process_Name=C:\\Program Files\\osquery\\osqueryd\\osqueryd.exe"
|
||||||
|
DEST_KEY = queue
|
||||||
|
FORMAT = nullQueue
|
||||||
|
|
||||||
|
[autoruns_wineventlog_null]
|
||||||
|
REGEX = "Script\sName\s=\sC\:\\Program Files\\AutorunsToWinEventLog\\AutorunsToWinEventLog.ps1"
|
||||||
|
DEST_KEY = queue
|
||||||
FORMAT = nullQueue
|
FORMAT = nullQueue
|
||||||
Reference in New Issue
Block a user