All,
I am trying to rename a subsect of logs. I am expecting the logs to get their source type renamed. But they remain WinEventLog:Application instread of Trend.
[WinEventLog:Application]
TRANSFORMS-wintrans = idx2trend,st2trend,route_stubhinfo_to_es_TU
[st2trend]
REGEX = Trend Micro OfficeScan Server[\S\s]+product_version
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::trend
It looks clean what you did. I would try maybe -
REGEX = (?m)^EventCode=(xxx|yyy)
Not sure exactly how you are collecting this data, but if that is with standard wineventlog inputs, I believe that sourcetype is already a transformed sourcetype and that process only runs once.
So you need to find the base sourcetype used by the windows TA. I believe that is WinEventLog
and use that in your props.conf stanza.