hello.. basically I would like to index all errors and warning and discard the rest. At the moment I am ONLY able to index errors and everything else is discarded, I would now want to index errors and warning.
what I have that is working for errors only
Props
[WMI:WinEventLog:Application]
TRANSFORMS-evtlog = nullQueue, errorOnly
Transforms.conf
[nullQueue]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue
[errorOnly]
REGEX=Error
DEST_KEY=queue
FORMAT=indexQueue
what I have tried for windows errors and warnings but does not works
[props]
[WMI:WinEventLog:Application]
TRANSFORMS-evtlog = nullQueue, errorOnly, warningOnly
[transforms]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue
[errorOnly]
REGEX=Error
DEST_KEY=queue
FORMAT=indexQueue
[warningOnly]
REGEX=Warning
DEST_KEY=queue
FORMAT=indexQueue
your help will be greatly appreciated...
... View more