Hi all,
How can I create a filter that sends just Syslog login and logout events? I have a Syslog on different machines that send syslog events to each their own forwarders and then come to indexer. How can I create a filter that has as sourcetype syslog?
thanks in advance,
Best regards.
here is your answer : Keep specific events and discard the rest
Here is an example, please time the regex to your events.
In props.conf, set the TRANSFORMS rule for any syslog soucretype
[syslog]
TRANSFORMS-filtersyslog= setnull,keeponlyloginlogout
Create a corresponding stanza in transforms.conf.
`
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[keeponlyloginlogout]
REGEX = (login|logout)
DEST_KEY = queue
FORMAT = indexQueue
`