hello ,
[host::TheHost]
TRANSFORMS-ReadData_bktfileserver = filter_ReadData
[WinEventLog:Security]
TRANSFORMS-filter4663 = filter_4663_readdata
[filter_4663_readdata]
REGEX = EventCode=4663.*?ReadData (or ListDirectory)
DEST_KEY = queue
FORMAT = nullQueue
I'm not quite sure I understood your question.
What do you mean by "filter"? Extracting the field or discarding it?
At the moment, you are creating the field "filter4663" in props.conf and tie it to your regex in transforms.conf, which gets discarded by FORMAT=nullQueue. So eventcode 4663 is replaced with nothing.
The regex doesn't seem to be valid, it should look like this:
REGEX = (?i)EventCode=4663.*ReadData\s\(or\sListDirectory\)
thanks for the answer,
the point is that i want to drop all eventcodes 4663 for Object access with message "ReadData", because i have too much logs. BUT 4663 is for DELETE either. thats why i want to filter based on message attached to eventcode.
Try this:
REGEX= "(?msi)EventCode=4663.*readdata|EventCode=4663.*listdirectory"
Good news. Feel free to accept the answer.
thanks. it works
That was the one I used for testing. I fixed it.
I tested this in the search window, and it worked fine.
why 4625? i want 4663