Hi,
I want to look at the host field and discard all hosts that begin with ISE. How would I do that? My understanding is that only certain regexes are available for host in transforms?
Like this:
In props.conf
:
[yourSourceTypeHere]
TRANSFORMS-remove_ISE_hosts = remove_ISE_hosts
In transforms.conf
:
[remove_ISE_hosts]
SOURCE_KEY = MetaData:Host
REGEX = "^ISE"
DEST_KEY = queue
FORMAT = nullQueue
You can read more about this at Filter Event Data and Send to Queues:
Does this read just the host field, or the entire raw event?
It reads just the host
field and if it starts with "ISE", the entire event will be skipped.