In my transforms.conf I have this filter that does not work
[dropevents]
REGEX = (?msi)^host=server1.*^EventCode=4674
DEST_KEY = queue
FORMAT = nullQueue
this does work but dropes events for all systems not just the one system
[dropevents]
REGEX = (?msi)^EventCode=4674
DEST_KEY = queue
FORMAT = nullQueue
My props.conf looks like this
[WinEventLog:Security]
TRANSFORMS-set=dropevents
I found that this works
(?msi)^EventCode=4674.*^ComputerName=(system22|system23|system01).*^Keywords=Audit Success.*SeBackupPrivilege
thanks to this site http://gskinner.com/RegExr/
use this site to evaluate your regex for filters
I found that this works
(?msi)^EventCode=4674.*^ComputerName=(system22|system23|system01).*^Keywords=Audit Success.*SeBackupPrivilege
thanks to this site http://gskinner.com/RegExr/
use this site to evaluate your regex for filters