Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

WinEvents Filtering on Heavy Forwarder (drop the end of event)

$
0
0
Hello guys I'm tring to drop the end of all Security events: This event is generated when a logon session is created. It is generated on the computer that was accessed. .... My conf files on Heavy Forwarder is: [transforms.conf] [win-event-cut-en] DEST_KEY = _raw REGEX = ((.*+[\v])+)(?=This event is generated when) FORMAT = $1 [props.conf] [WinEventLog:Security] TRANSFORMS-windows_events =win-event-cut-en It's not works.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>