Splunk Enterprise

Event filter on WEC vs Event blacklist on UF

adalbor
Builder

Hey All,

I am comparing two routes to blacklist/filter events.

1) Filter events out at our WEC's using the event filter
2) Blacklist the events on the Universal Forwarders

We currently have different events filtered/blacklisted in both areas but I want to consolidate for mgmt purposes and for ease of use.
If there any benefits to either or?

Filtering on the WEC means its not collecting the events period saving storage space and resource usage. I cant find anywhere though that documents or defines any performance hits by doing that on the WEC subscriptions.

I do love that I can use a regex to filter out specific things like process names on 4688's on the UF.

I was thinking filter out all full events I don't want on the WEC then using the blacklist on the UF to filter out specific events from certain event types like the 4688.

Any thoughts or guidance?

Thanks!
Andrew

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

The benefit of filtering at the UF is the ability to easily change the blacklisting. If you are filtering out things at the WEC, then the data isn't there at all. So, in short, if you think you might need it at some point, then I would say to collect it and blacklist.

0 Karma

sloshburch
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...