Post some sample data and we can give you some working regex to go with it.
from the document, To discard specific events and keep the rest
This example discards all sshd events in /var/log/messages by sending them to nullQueue:
[source::/var/log/messages]
TRANSFORMS-null= setnull
2. Create a corresponding stanza in transforms.conf. Set DEST_KEY to "queue" and FORMAT to "nullQueue":
[setnull]
REGEX = [sshd]
DEST_KEY = queue
FORMAT = nullQueue
That does it.
could you please update us the http error log and few 301 and 302 sample messages
Read up on the basic tenchique here (it is pretty strightforward):
http://docs.splunk.com/Documentation/Splunk/6.1.5/Forwarding/Routeandfilterdatad